A newly documented ClickFix campaign is tricking Windows users into running fake fix commands that abuse the legitimately signed IBM SPSS WinWrap Basic IDE executable, WinWrapIDE.exe, to sideload malicious DLLs and deploy a previously undocumented remote access trojan named CNCMachineRMS. Researchers said the intrusion chain uses four decoy DLLs, invokes shellcode through the Windows EnumTimeFormatsEx API, and relies on an external configuration file, HelperStandardizationApplication.bin, that contains both script logic and the embedded final payload. The staged, memory-heavy design is intended to make intermediate samples appear benign and reduce detection during automated analysis.
CNCMachineRMS is described as a hands-on-keyboard access tool with broad post-compromise capabilities, including an interactive shell, file management, screenshot capture, local account creation, staged payload retrieval, and multiple persistence options such as Run keys and scheduled tasks masquerading as IBM SPSS components. The 64-bit implant reportedly builds strings at runtime, uses a custom binary container and scripting language, profiles hosts for domain and privilege context, beacons every 600 seconds, and may use DNS over HTTPS to hide resolution activity. Defenders are being urged to isolate affected hosts, preserve volatile evidence, investigate local account and privilege changes, reset exposed credentials, and hunt for lateral movement or second-stage compromise on neighboring systems.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Using FlowCarp and sandbox-linked samples, researchers expanded CNCMachineRMS infrastructure to four TCP/443 C2 servers, adding 89.124.79.98 and 144.124.242.171 alongside previously known hosts. The reporting also introduced the domain triotmelon[.]com and showed CNCMachineRMS activity continuing into August 2026.
On 2026-04-23, researchers documented SmartApeSG activity using a fake CAPTCHA and ClickFix-style social engineering chain that led victims to download a password-protected ZIP from solidpathcore.com containing a legitimate software package bundled with a malicious DLL for side-loading. After infection, the host communicated with 89.110.110.119 over TCP/443 using encoded or encrypted non-TLS traffic and established persistence through a Registry change and a scheduled task.
Researchers first identified the previously unknown CNCMachineRMS binary command-and-control protocol in April 2026 from packet captures of ClickFix fake-CAPTCHA infections. The analysis showed the RAT communicating over TCP/443 without TLS and enabled defenders to detect the protocol with FlowCarp while expanding known C2 infrastructure.
The reporting disclosed that CNCMachineRMS is a 1.14 MB x64 implant with a custom scripting language, interactive shell, file management, screenshot capture, local account creation, seven persistence methods, and 20 typed commands for staging additional payloads. The analysis also identified command-and-control indicators including notepadreleased[.]com and 85[.]158.110.78 over TCP/443, plus DNS-over-HTTPS resolution through dns.google, cloudflare-dns.com, and dns.quad9.net.
Researchers documented an intrusion chain in which a ClickFix lure tricks victims into running a command that launches the legitimately signed IBM SPSS WinWrap Basic IDE binary, WinWrapIDE.exe, to activate COM-based scripting and load a staged DLL chain. The chain culminates in shellcode execution through EnumTimeFormatsEx, a BabaDeda stage, and loading of the previously undocumented CNCMachineRMS remote administration implant from HelperStandardizationApplication.bin.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 35 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
netresec.com
Open sourcenetresec.com
Open sourcecyberaccord.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcelevelblue.com
Open sourcemalware-traffic-analysis.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.