Threat actors are compromising legitimate websites and injecting fake browser-update prompts that redirect visitors through traffic-filtering infrastructure to malware downloads. The campaigns, including SocGholish, ClearFake, RogueRaticate/FakeSG and others, tailor lures to victims’ browsers and commonly deliver remote-access tools, loaders, and credential stealers such as NetSupport RAT, Lumma, StealC, Redline, Raccoon v2, and SectopRAT. Users may reach affected sites through routine browsing, search results, social-media links, or previously legitimate links in email and newsletters.
ClearFake activity has used the IDAT loader—also tracked as GHOSTPULSE, HIJACKLOADER, or IDATLOADER—to stage payloads through fake Chrome updates, MSI installers, DLL side-loading, process injection, Process Doppelgänging, and evasion of user-mode security hooks. GHOSTPULSE initially concealed encrypted payloads in PNG IDAT chunks and later shifted to embedding data in PNG pixel values; recent delivery also includes fake CAPTCHA pages that trick users into running clipboard-injected PowerShell commands. Organizations should block or restrict unapproved browser and application installers, monitor PowerShell, DLL side-loading, suspicious MSIX installs, and browser-initiated downloads, and train users to reject update or CAPTCHA prompts presented by websites.

Pull IOCs and campaign context straight into your stack.
16 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos documented ZigCryptoStealer, a Windows clipboard-address replacement malware, as an additional payload in a ClearFake/Amatera infection chain. The reported ZIP-delivered branch abused a legitimate Chrome executable for DLL side-loading, injected into explorer.exe, and could use a vulnerable driver to terminate security processes.
Elastic created the Windows_Trojan_Blister YARA rule for updated BLISTER variants; the rule was subsequently modified on August 8.
Third-party researchers publicly described the ClearFake fake browser-update cluster, which Proofpoint subsequently began tracking.
Elastic observed a stream of low-detection BLISTER samples in the wild. The variants hid encrypted malicious code in legitimate application components, including VLC Media Player DLLs, and added environmental keying and EDR-evasion capabilities.
The ClearFake fake-browser-update campaign began, redirecting victims from compromised websites to spoofed browser-update prompts and malicious downloads.
By late July, BLISTER campaigns were targeting organizations to deploy the MYTHIC command-and-control implant through an updated SocGholish infection chain; observed MYTHIC activity ran in an injected WerFault.exe process.
Rapid7 first spotted the IDAT loader, a multi-stage loader that conceals encrypted payloads in PNG IDAT chunks and was observed delivering StealC, Lumma, and Amadey infostealers.
Proofpoint identified ZPHP/SmartApeSG, a fake browser-update cluster that delivers base64-encoded ZIP payloads containing JavaScript for NetSupport RAT and, in some cases, Lumma Stealer.
An early BLISTER sample appeared to be a non-production test loader and displayed a message box containing the string "Test."
Proofpoint first identified the RogueRaticate/FakeSG fake-browser-update cluster, which injects obfuscated JavaScript into compromised websites and uses traffic filtering infrastructure.
RogueRaticate (FakeSG) activity may have begun in the wild, using fake browser-update lures and later commonly leading to NetSupport RAT infections.
Elastic Security Labs initially discovered the financially motivated BLISTER Windows malware loader.
Elastic Security Labs released ghostpulse_payload_extractor.py, a Python tool that processes GHOSTPULSE encrypted files to recover malware stages, the final payload, and configuration. The tool supports single-file and directory processing and requires Python 3.10 or later plus Elastic's nightMARE library.
GHOSTPULSE updated its second-stage concealment from encrypted PNG IDAT chunks to image pixel values. Recent campaigns used fake CAPTCHA lures to induce clipboard-command execution and deployed GHOSTPULSE as a loader for Lumma Stealer.
Elastic observed GHOSTPULSE distributed through malicious code-signed MSIX packages impersonating installers for Chrome, Brave, Edge, Grammarly, and WebEx. The loader used DLL sideloading, module stomping, direct NT API calls, and Process Doppelgänging to deploy payloads including SectopRAT, Rhadamanthys, Vidar, Lumma, and NetSupport.
Elastic Security Labs uploaded a GHOSTPULSE indicator repository containing ECS NDJSON and STIX bundle indicator files for the campaign involving malicious MSIX executables and defense-evasion techniques.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 49 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
10 references tracked. Mallory keeps watching after this page renders.
trojan-killer.net
Open sourceelastic.co
Open sourceelastic.co
Open sourceelastic.co
Open sourceelastic.co
Open sourcegithub.com
Open sourcegithub.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.