ClickFix Evolves: Three New Malware Loaders Deliver Ransomware and RATs Across Enterprise Networks

Three new ClickFix malware loaders, BabaDeda, Lorem Ipsum, and Potemkin, are delivering ransomware and RATs across enterprise networks. Education and finance are primary targets. GCC defenders must act.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region5 min read
Enterprise security analyst reviewing a ClickFix social engineering alert on a corporate SOC workstation as researchers disclose three new malware loaders delivering ransomware and remote access trojans

Enterprise security analyst reviewing a ClickFix social engineering alert on a corporate SOC workstation as researchers disclose three new malware loaders delivering ransomware and remote access trojans

Security researchers at Morphisec, BlueVoyant, and Huntress have independently documented three new malware loader families being distributed through ClickFix campaigns, each with distinct delivery mechanisms, evasion techniques, and final-stage payloads. The research, published on 16 June 2026, confirms that ClickFix has matured from an opportunistic social engineering tactic into a structured delivery ecosystem supporting multiple threat actors and ransomware groups simultaneously.

ClickFix is a social engineering technique that deceives users into running attacker-supplied commands by presenting fake browser errors, captcha prompts, software update notifications, or troubleshooting instructions that appear legitimate. The user is instructed to open a command prompt or Run dialog and paste in a command, which then executes a malicious payload with the user's own permissions. No exploit, no phishing attachment, no software vulnerability is required. The attack works because it looks like a routine IT support action.

The three new loaders disclosed this week each represent an evolution of that basic technique.

  • BabaDeda Loader, documented by Morphisec, was observed in April 2026 targeting education and financial organisations. It builds on a crypter service first documented by Morphisec in 2021 but has been significantly expanded into a modular loader built for stealth and payload flexibility. The loader profiles the host on first execution, avoids running on Russian or Belarusian systems, and performs security product checks before retrieving its main payload. It injects the final payload into a trusted Windows process such as svchost.exe. Delivered payloads include a .NET backdoor capable of harvesting browser credentials, cookies, browsing history, and saved passwords, extracting files based on configurable rules, capturing screenshots, and establishing an encrypted channel to a command-and-control server. A second delivery chain using BabaDeda drops DanaBot and SectopRAT via DLL side-loading using a staged component called Storage Crypter that hides payloads in external storage-like files, minimising forensic visibility and complicating automated analysis.
  • Lorem Ipsum Loader, documented by BlueVoyant, is attributed with high confidence to Vanilla Tempest, a financially motivated threat actor also known as Vice Society and Rapid Brigantine, which has previously deployed ransomware families including Rhysida, BlackCat, Zeppelin, and Quantum Locker. The loader has been active since February 2026 and was previously distributed through trojanised Microsoft Teams installers. A recent Microsoft disruption of the signing certificate supply used by the group forced the operators to pivot to ClickFix lures hosted on at least five compromised WordPress sites spanning architecture, legal services, and construction technology sectors. The attack uses an outdated Node.js version to execute JavaScript payloads that deploy a DLL side-loading chain establishing persistence, followed by the Lorem Ipsum Backdoor, which retrieves next-stage payloads from attacker-controlled social media profiles and ultimately delivers Rhysida ransomware.
  • Potemkin Loader, documented by Huntress, is a custom 64-bit loader using a domain generation algorithm to locate its command-and-control infrastructure, making it resistant to domain-based blocking. It reflectively loads follow-on modules in memory, leaving minimal disk artefacts. The loader delivers EtherRAT and RMMProject, a Lua-scriptable module enabling remote screen control, browser credential theft via Chromium App-Bound Encryption bypass, screenshot capture, and arbitrary code execution. Huntress observed hands-on keyboard activity following initial access, including Microsoft Defender exclusion configuration, Chisel reverse SOCKS tunnel deployment, Cloudflare tunnel setup for persistent access, and lateral movement via WMIExec and SMBExec to domain controllers, spreading EtherRAT across more than 11 hosts in a single campaign.

A fourth ClickFix variant documented in the same research period exploited interest in AI tools specifically, using fake MSI installers for AI assistants to deliver PowerShell payloads. As Gulf enterprises accelerate AI adoption, this variant carries particular relevance for GCC security teams managing the intersection of AI tooling rollout and endpoint security policy.

The persistence of ClickFix as an effective delivery mechanism rests on a fundamental characteristic of enterprise environments: users are accustomed to following technical instructions and trust prompts that look like IT support or routine software actions. The tactic does not require sophistication. It requires only that the lure looks familiar. Huntress researchers note that the social engineering does not need to be sophisticated; it just needs to look like a legitimate troubleshooting step, and more often than not that is sufficient.

For GCC enterprise security teams, several immediate defensive actions are warranted. Restrict or monitor the Windows Run dialog and PowerShell execution policies at the endpoint level. Deploy security awareness training specifically addressing ClickFix-style lures, which differ meaningfully from traditional phishing in that they instruct the user to take an action rather than click a link. Ensure EDR coverage includes memory-resident loader detection and DLL side-loading alerting. Monitor for Chisel, Cloudflare tunnel, and WMIExec activity as indicators of post-compromise lateral movement. As GCC enterprises continue to scale their security operations, the human element of the attack chain remains one of the most difficult vectors to eliminate through technical controls alone, making scenario-specific awareness training a non-negotiable layer of defence.

The financial and education sector focus of BabaDeda is directly applicable to the GCC. Banking, financial services, and higher education institutions across the UAE and Saudi Arabia represent high-value targets for credential theft and ransomware deployment, and the modular, evasion-focused architecture of these new loaders means that signature-based detection alone will not be sufficient. Behavioural detection, endpoint isolation capability, and tested incident response runbooks for ransomware scenarios are the minimum expected standard for any enterprise security programme operating in the region in 2026.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Ransomware Threat Landscape GCCSocial Engineering and Malware Delivery 2026Endpoint Security Enterprise MENAClickFix Attack Chain AnalysisMalware Loader Evolution 2026Enterprise SOC Detection GCCMENA Threat Intelligence 2026