TGTGInsighttelegram intelligenceLIVE / telegram public index
Post content
Post content
⚠️ A new ClickFix variant abuses Win+R to mount a remote WebDAV drive and run malware. It launches a trojanized WorkFlowy Electron app that beacons to C2 every 2 seconds. Atos says it bypassed Microsoft Defender and surfaced only through threat hunting. 🔗 Inside: WebDAV trick + ASAR injection → https://thehackernews.com/2026/03/investigating-new-click-fix-variant.html