11-09-2026
I only trusted a security verification window… Beware of LegionLoader malware being distributed via the ClickFix method
https://asec.ahnlab.com/ko/95373/
Report completeness: Medium
Threats:
Legionloader
Clickfix_technique
Process_injection_technique
Process_hollowing_technique
Victims:
Namuwiki users
Geo:
Korean
TTPs:
Tactics: 1
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1005, T1016.001, T1027.013, T1036, T1055, T1055.012, T1059.001, T1082, T1105, T1140, have more...
IOCs:
Command: 1
Domain: 18
IP: 1
Url: 4
File: 2
Hash: 5
Soft:
Chrome
Algorithms:
rc4, base64, md5
Languages:
powershell