Skip to content

ThreatLocker MDR Intercepts ClickFix Attack Delivering Evolved ACR Stealer and GhostPipe

ThreatLocker MDR intercepted a ClickFix attack that used steganography and obfuscation to deploy an evolved ACR stealer and a Google-phishing payload called GhostPipe.

Two smartphones showing ThreatLocker MDR intercept notifications and a blocked call screen
Credit: ThreatLocker

ThreatLocker MDR intercepted a ClickFix attack in a client environment that deployed a substantially updated version of ACR stealer alongside a previously undocumented secondary payload designed to steal Google credentials through an adversary-in-the-middle phishing proxy.

ThreatLocker traced the attack to a fake captcha prompt served from bamscompleteav.com, a legitimate Audio/Visual company in Lubbock County, Texas whose website had been compromised. The prompt instructed users to paste an obfuscated PowerShell command into the Windows Run dialog, starting a five-stage chain that combined steganographic payload extraction with layered runtime obfuscation.

The first stage arrived as a file with valid MP3 header bytes embedding a real audio track, allowing it to pass VirusTotal inspection despite matching several crowdsourced Sigma rules. VBScript hidden inside the file created a scheduled task and fetched a 79,000-line obfuscated PowerShell script from a malicious domain. ThreatLocker MDR's analysis identified that script as a custom steganography loader: it downloaded a JPEG image, derived executable byte values from the mean RGB intensity of each 8x8 pixel block, decrypted the result using XOR and GZip decompression, and launched a shellcode loader entirely in memory.

The version of ACR stealer deployed here marks a clear departure from prior samples. Where earlier builds were largely unobfuscated, this one uses control flow flattening with randomized 32-bit state constants, opaque predicates, and string encryption backed by an additional XOR pass, making static analysis considerably slower. Its C2 domain resolves through HTTPS DNS-over-HTTPS on port 443 rather than standard DNS on port 53, sidestepping network-layer controls that monitor for plaintext DNS queries. Once connected, the C2 issues configuration controlling exactly what is collected: browser login stores, cryptocurrency wallet files, Steam session data, local files, and desktop screenshots are all in scope, with exfiltration handled over HTTPS with built-in retry logic.

A secondary payload retrieved from the C2 server, referred to internally as GhostPipe, ran an adversary-in-the-middle attack aimed solely at Google accounts. It established persistence by copying itself into Chrome's update folder and writing a Run registry key, then modified Chrome shortcuts to redirect accounts.google.com to a locally hosted phishing proxy fronted by a forged certificate. Credentials and any MFA tokens entered during a login session were relayed in real time to a remote server, with few artifacts remaining beyond altered shortcut flags and a forged certificate entry in the Windows store.

ThreatLocker MDR detected the image payload download when its Ringfencing policy blocked PowerShell from making outbound network requests. Application Allowlisting had already prevented MSHTA execution at the attack's entry point, stopping the chain before the steganographic loaders and credential-theft stages could run. The ThreatLocker MDR team noted the incident shows that default-deny application control can neutralize ClickFix attacks even when attackers combine well-documented social engineering lures with heavily obfuscated multi-stage payloads.

Share this story

Grace Sullivan

Grace Sullivan writes for the techshooked news desk, covering breaking technology stories across the site's beats. She works to the daily news standard: lead with what happened, name the source, and separate confirmed fact from claim.