TI Mindmap HUB
Threat Intelligence Report

HellsUchecker: ClickFix to blockchain-backed backdoor

๐Ÿ“… March 20, 2026 ๐Ÿ“ฐ www.derp.ca ๐Ÿ” 0 CVE(s) referenced

HellsUchecker is a memory-only backdoor delivered via a 10-stage chain that starts with a fake CAPTCHA, uses Windows LOLBins and blockchain smart contracts for stealthy payload and C2 distribution, and employs direct syscalls for undetectable injection, making detection extremely difficult.

researcher

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle