User interaction with a ClickFix-style phishing site resulted in execution of an obfuscated PowerShell command
Reported 29 Apr 2026 by otx · Severity: medium
A ClickFix-style phishing campaign leveraged social engineering to trick users into executing obfuscated PowerShell commands that downloaded and installed a malicious MSI payload from a remote server. The attack employed a sophisticated multi-stage infection chain utilizing DLL s