Skip to content

Campaign record

XFiles Stealer via early IClickFix

Emmenhtal Loader and XFiles Stealer delivered by the early IClickFix WordPress injection

Status as last assessed
Archived
First seen
2024-12-18
Last seen
2025-02-01
Indicators
5
Sources
1
Targets
Windows
  • Fake CAPTCHA verification
  • Emmenhtal Loader
  • XFiles Stealer
  • Compromised WordPress site

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

An earlier build of the same WordPress-injection cluster, examined by Sekoia.io in February 2025, carried a different payload chain. Around 160 sites bore the marker tag at that point, nothing filtered incoming traffic, and one script fetched through a Short.gy shortlink held the lure, the clipboard code and the command together. The counterfeit Cloudflare page of that period spelled out keyboard steps instead of presenting a challenge a visitor would already recognise, which Sekoia judges the weaker of the two designs. Anyone who complied downloaded an MSI installer, a build of Emmenhtal Loader, which then retrieved XFiles Stealer. Sekoia assigned this activity to the IClickFix cluster only in retrospect, after working through the framework's later NetSupport RAT stage at the end of 2025.

Overlap with other campaigns

We compared the 5 indicators in this record — covering 2 distinct registrable domains — against the 43 other published campaigns in this corpus.

  • No indicator is shared, but the two records use the same registrable domains.

    Shared registrable domain (1)

    • domain, shown defanged for safety: short dot gy

A shared indicator is the same record cited by both campaigns. A shared registrable domain is weaker evidence and is counted separately, because two campaigns can share a registrable simply by renting subdomains from the same platform.

What changed since publication

The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.

Indicators checked
1 of 5
Checks recorded
2
Checks since publication
2
Never checked
4

Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology. 4 indicators have never been checked by us at all.

Current recorded state

  • 1 Unregistered
  • 4 Not checked by us

Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.

Execution mechanisms

How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.

Execution mechanisms recorded for this campaign, with their frequency across the corpus
MechanismAcross the corpusATT&CK
Windows Run dialog23 of 4452%T1204.004
Clipboard injection15 of 4434%T1204.004

Both of these mechanisms appear together in 10 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.

Indicators

5 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentFirst seenStateReport an error
domain, shown defanged for safety: qq525f dot short dot gydomainRedirectorShared platform2025-01-09Not checked by usReport an error in domain record 1d25cef3-f0c7-41b9-9999-9b0a0abda1ee
url, shown defanged for safety: hxxp colon slash slash qq525f dot short dot gy/claudurlRedirectorShared platform2025-02-01Not checked by usReport an error in url record 78ccd60d-761d-429a-b869-5cd82cdef8cc
url, shown defanged for safety: hxxps colon slash slash qq525f dot short dot gy/1urlDownload URLShared platform2025-02-01Not checked by usReport an error in url record ec8cfa12-fd35-4629-8390-767e7ca63f5c
domain, shown defanged for safety: bestieslos dot comdomainStagingAttacker-controlled2024-12-18Unregistered2026-08-22Report an error in domain record 367c13ef-0407-4c33-85c5-80cba173c2e8
url, shown defanged for safety: hxxps colon slash slash bestieslos dot com/over dot jsurlStagingAttacker-controlled2025-02-01Not checked by usReport an error in url record ac904340-742c-412b-9195-acac3c08a25e

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “XFiles Stealer via early IClickFix”, campaign ID 61ac3fa9, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/61ac3fa9/iclickfix-emmenhtal-xfiles-stealer

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.