Threat Actors Abuse Trusted Business Infrastructure to Host Infostealers
Recent developments in cybercrime reveal a new cycle of malware infection, where victims are unknowingly turned into attackers. Research by the Hudson Rock Threat Intelligence Team and ClickFix Hunter platform shows that many domains hosting the…
Recent developments in cybercrime reveal a new cycle of malware infection, where victims are unknowingly turned into attackers. Research by the Hudson Rock Threat Intelligence Team and ClickFix Hunter platform shows that many domains hosting the "ClickFix" malware are legitimate businesses compromised by infostealers.
Throughout 2024 and 2025, the "ClickFix" method evolved into a prevalent threat. Unlike traditional attacks exploiting browser vulnerabilities, ClickFix deceives users by imitating trusted interfaces such as Google reCAPTCHA, Chrome updates, or Microsoft error screens. This trick leads users to execute a script via the Windows Run dialog, which evades traditional security measures like SmartScreen, and installs infostealers directly into memory.
The report highlights the cyclical nature of this malware ecosystem. ClickFix Hunter monitors over 1,635 active domains, with 588 identified in the last 30 days. Analysis of Hudson Rock’s Cavalier™ intelligence shows that approximately 13% of these sites appear in compromised credential databases, indicating a feedback loop:
Infection: A user is infected by an infostealer. Exfiltration: Credentials for assets like WordPress admin panels are stolen. Compromise: Attackers use these credentials to hijack websites. Distribution: The hijacked site is used to spread the ClickFix malware.
Recent developments in cybercrime reveal a new cycle of malware infection, where victims are unknowingly turned into attackers.
The report identifies cases such as jrqsistemas.com and wo.cementah.com as ClickFix hosts. Hudson Rock's data revealed administrative credentials for these sites were previously stolen by malware. For jrqsistemas, WordPress login details were found in a malware log, illustrating how the site was compromised.
This model thrives on large-scale credential theft and social engineering. Since attack infrastructure is spread across numerous legitimate businesses, rather than centralized servers, it complicates takedown efforts.
The security community is increasingly using context-aware tools to differentiate between malicious and compromised legitimate domains. ClickFix Hunter, developed by Carson Williams, incorporates Hudson Rock's API to aid in this distinction, which is crucial for breaking the feedback loop by securing digital identities.
Based on reporting by GBHackers.
