Zenonimo's Threat Research

ClickFix - EtherHiding - Jpeg Stego - AiTM proxy

Six layers deep: ClickFix to browser-in-the-middle

A compromised UK trade-association site, a config fetched from the Base blockchain, and a fake CAPTCHA get one line into the victim’s Run box. Six decoding layers later - including a payload hidden in the brightness of a JPEG - the chain lands a local TLS proxy that puts the attacker inside the victim’s Chrome session.

ClickFix - EtherHiding - Jpeg Stego - AiTM proxyLead analysis
Index · all reports1 entries

One report so far. The index fills in as you publish.

Zenonimo's Threat Research