Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend.
Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
In mid-July 2026, visitors to new-blog.artlist[.]io were shown a fake CAPTCHA that tricked them into running a hidden PowerShell command. That downloader fetched additional staged components and ultimately installed a full-featured remote-access trojan with capabilities including credential theft, remote desktop, file transfer, and Tor/SOCKS-based C2 fallback.
Using the stolen WordPress credentials, attackers accessed the backend for new-blog.artlist[.]io and injected obfuscated JavaScript. The malicious code used an EtherHiding technique that queried a Polygon smart contract to retrieve the next-stage host auth-code-check[.]info.
In August 2023, an Israeli freelance WordPress developer downloaded a pirated copy of Adobe Acrobat Pro DC and was infected by an infostealer. The malware exposed saved WordPress credentials for Artlist, which researchers later linked to the subsequent compromise.
On 2026-07-14, researchers publicly documented the malicious injection on new-blog.artlist[.]io and analyzed the infection chain from EtherHiding through the final native RAT. The reporting also described the staged archive, DLL side-loading, shellcode and container parsing, and backend token behavior observed during artifact recovery.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 350 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcetrojan-killer.net
Open sourceinfostealers.com
Open sourcemalware.news
Open sourcereddit.com
Open sourcederp.ca
Open sourcecommunity.gurucul.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.