Campaign record
Rhadamanthys in a fake update lure
Rhadamanthys delivered by a full-screen fake Windows Update lure
- Status as last assessed
- Active
- First seen
- 2025-10-01
- Last seen
- 2025-11-19
- Indicators
- 21
- Sources
- 1
- Targets
- Windows
- Fake Windows Update screen
- Rhadamanthys
Original research
- Huntress2025-11-24Vendor researchFirst account
ClickFix Gets Creative: Malware Buried in Images
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
From the start of October, Huntress recorded a second lure feeding the same steganographic loader. Here the browser was pushed into full screen and dressed up as the blue update splash, animations included, before the viewer was asked to open the Run box and paste a line already sitting on the clipboard. The page source was not obfuscated, carried Russian comments, and posted each interaction to a statistics script, which gave Huntress a urlscan pivot for finding more sites. Five partner incidents between 1 and 17 October used one address for both the mshta stage and the PowerShell behind it, with only the filename rotating; the operator later moved the second-stage domain but kept the address. The payload at the end was Rhadamanthys, not Lumma. A takedown of Rhadamanthys infrastructure was announced on 13 November, yet more sites still served the lure on 19 November.
What changed since publication
The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.
- Indicators checked
- 1 of 21
- Checks recorded
- 2
- Checks since publication
- 2
- Never checked
- 20
Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology. 20 indicators have never been checked by us at all.
Current recorded state
- 1 Unregistered
- 20 Not checked by us
Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.
Execution mechanisms
How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.
| Mechanism | Across the corpus | ATT&CK |
|---|---|---|
| Windows Run dialog | 23 of 4452% | T1204.004 |
| PowerShell | 19 of 4443% | T1059.001 |
| Clipboard injection | 15 of 4434% | T1204.004 |
| mshta.exe | 7 of 4416% | T1218.005 |
| PNG pixel-data steganography loader | 2 of 445% | T1027.003 |
All 5 of these mechanisms appear together in 2 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.
Indicators
21 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account or any overlap with another campaign in this corpus. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “Rhadamanthys in a fake update lure”, campaign ID 018c699e, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/018c699e/rhadamanthys-fake-windows-update-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.