Active c-ares DLL sideloading malware campaign targeting finance and supply chain staff
Campaign
Summary
Hide ▲
Show ▼
Security researchers at Trellix disclosed an active malware campaign that abuses a malicious libcares-2.dll beside signed GitKraken ahost.exe binaries to bypass security controls. The operation delivers commodity trojans and stealers including Agent Tesla, CryptBot, Formbook, Lumma Stealer, Vidar Stealer, Remcos RAT, Quasar RAT, DCRat, and XWorm. Targets include employees in finance, procurement, supply chain, and administration across sectors such as oil and gas and import and export, with multilingual invoice- and RFQ-themed lures used to prompt execution of the rogue DLL-loading binary.
Related Happenings
ClickFix attacks with PySoxy scheduled-task persistence
Malware Activity
H score22
First: 12.05.2026 15:00
Last: 12.05.2026 15:00
Sources 1
About this happening:
Cybercriminals are combining ClickFix with PySoxy to preserve access on victim machines, letting activity restart even after removal attempts. The setup uses a Python SO...
ClickFix attacks with PySoxy scheduled-task persistence
Malware ActivityAbout this happening: Cybercriminals are combining ClickFix with PySoxy to preserve access on victim machines, letting activity restart even after removal attempts. The setup uses a Python SO...
ACSC ClickFix mitigation guidance for Vidar Stealer
Advisory/Mitigation
H score34
First: 07.05.2026 21:00
Last: 07.05.2026 21:00
Sources 1
About this happening:
The ACSC issued mitigation guidance for an ongoing ClickFix campaign that is pushing Vidar Stealer through malicious PowerShell commands, increasing credential-the...
ACSC ClickFix mitigation guidance for Vidar Stealer
Advisory/MitigationAbout this happening: The ACSC issued mitigation guidance for an ongoing ClickFix campaign that is pushing Vidar Stealer through malicious PowerShell commands, increasing credential-the...
LeakNet ransomware gang ClickFix and Deno in-memory loader activity
Malware Activity
H score23
First: 17.03.2026 14:09
Last: 17.03.2026 14:09
Sources 1
About this happening:
The LeakNet ransomware gang has adopted ClickFix initial access and a Deno-based loader that executes malicious code in memory, making intrusions harder to detect and...
LeakNet ransomware gang ClickFix and Deno in-memory loader activity
Malware ActivityAbout this happening: The LeakNet ransomware gang has adopted ClickFix initial access and a Deno-based loader that executes malicious code in memory, making intrusions harder to detect and...
ClickFix MacSync social-engineering campaign targeting macOS users
Campaign
H score38
First: 16.03.2026 13:41
Last: 16.03.2026 13:41
Sources 1
About this happening:
ClickFix campaigns continued to blend fake verification pages with command-pasting lures, including a 2025-11-06 wave that used embedded video tutorials, automatic O...
ClickFix MacSync social-engineering campaign targeting macOS users
CampaignAbout this happening: ClickFix campaigns continued to blend fake verification pages with command-pasting lures, including a 2025-11-06 wave that used embedded video tutorials, automatic O...
Hive0163 extortion and ransomware campaign using ClickFix and malvertising
Campaign
H score35
First: 12.03.2026 19:02
Last: 12.03.2026 19:02
Sources 1
About this happening:
Hive0163 is running an active extortion and ransomware campaign that expands access and raises the risk of large-scale data exfiltration. The operation uses ClickFix,...
Hive0163 extortion and ransomware campaign using ClickFix and malvertising
CampaignAbout this happening: Hive0163 is running an active extortion and ransomware campaign that expands access and raises the risk of large-scale data exfiltration. The operation uses ClickFix,...
Timeline
-
14.01.2026 16:18 3 articles · 6mo ago
c-ares DLL sideloading campaign targets business staff
Initial DisclosureAn active malware campaign abuses a malicious libcares-2.dll beside signed GitKraken ahost.exe binaries to bypass security controls and deliver commodity trojans and stealers, including Agent Tesla, CryptBot, Formbook, Lumma Stealer, Vidar Stealer, Remcos RAT, Quasar RAT, DCRat, and XWorm. The operation targets employees in finance, procurement, supply chain, and administration roles across commercial and industrial sectors such as oil and gas and import and export, using multilingual invoice and RFQ-themed lures to get victims to execute the rogue DLL-loading binary.
Show sources
- Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware — thehackernews.com — 14.01.2026 16:18
- Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware — thehackernews.com — 14.01.2026 16:18
- Initial access hackers switch to Tsundere Bot for ransomware attacks — www.bleepingcomputer.com — 29.01.2026 01:29