TGTGInsighttelegram intelligenceLIVE / telegram public index
← The Hacker News
The Hacker News avatar

TGINSIGHT POST

Post #8602

@thehackernews

The Hacker News

Views11,100Post view count
PostedMar 1603/16/2026, 09:55 AM
Post content

Post content

⚠️ A new ClickFix variant abuses Win+R to mount a remote WebDAV drive and run malware. It launches a trojanized WorkFlowy Electron app that beacons to C2 every 2 seconds. Atos says it bypassed Microsoft Defender and surfaced only through threat hunting. 🔗 Inside: WebDAV trick + ASAR injection → https://thehackernews.com/2026/03/investigating-new-click-fix-variant.html