TI Mindmap HUB
Threat Intelligence Report

ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery

📅 June 6, 2026 📰 www.levelblue.com/ 🔍 0 CVE(s) referenced

The latest ClickFix campaign leverages sophisticated social engineering, abusing trusted job platforms and legitimate Windows and Python tools to deliver fileless, multi-stage malware—including the CastleLoader MaaS and a Python-based RAT—via a stealthy, browser-driven infection chain that evades detection and enables full remote control of compromised systems.

unclassified

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle