Back to Intelligence

ClickFix Social Engineering Delivers Lumma Stealer & SectopRAT; Void Arachne's ValleyRAT Hides in QN Wallpaper Adware — OTX Pulse Detection Pack

SA
Security Arsenal Team
September 30, 2026
10 min read

Two concurrent OTX pulses paint a picture of a maturing social-engineering-to-RAT pipeline that enterprise defenders must treat as a single defensive problem even though the actors differ.

Pulse 1 — ClickFix via ChatGPT Custom GPTs (AlienVault, 2026-09-29): Unknown threat actors are purchasing sponsored Google search results to funnel victims to attacker-controlled ChatGPT Custom GPTs impersonating legitimate assistants. From there, victims are redirected to a malicious Google Sites page presenting a fake Cloudflare CAPTCHA — the hallmark ClickFix technique. The victim is socially engineered into copying and executing an obfuscated PowerShell command, which bootstraps a multi-stage chain delivering Lumma Stealer, SectopRAT, MacSync, and AMOS (Atomic macOS Stealer). The use of "canon sideloading" — abusing signed, legitimate binaries to load malicious payloads — indicates deliberate defense evasion. This is a cross-platform operation targeting both Windows and macOS users indiscriminately, monetizing stolen credentials and session tokens while establishing persistent RAT access.

Pulse 2 — ValleyRAT disguised as QN Wallpaper adware (Void Arachne, 2026-09-30): Void Arachne, a Chinese-language threat actor, is distributing the ValleyRAT backdoor bundled inside a trojanized installer for "QN Wallpaper," a legitimate Chinese wallpaper/adware application. The installer deploys a modified-but-functional wallpaper tool as cover while using DLL sideloading through a signed process to execute the backdoor. ValleyRAT provides keylogging, clipboard monitoring, screenshot capture, and secondary payload delivery. Targeting is concentrated in China and India, consistent with Void Arachne's known focus on Chinese-speaking users via SEO poisoning and malvertising.

Collective assessment: Both campaigns exploit the same trust primitives — legitimate platforms (OpenAI's GPT store, Google Sites, Google Ads, signed Chinese software) — to bypass perimeter controls. Both terminate in commodity or semi-commodity RAT/stealer payloads loaded via sideloading. The detection surface is therefore convergent: unsigned DLLs loaded by signed processes, user-initiated PowerShell spawned from browsers, and masqueraded installers.

Threat Actor / Malware Profile

Unknown Actor — ClickFix Distribution Cluster

  • Distribution method: Sponsored Google search ads → malicious Custom GPTs → Google Sites fake CAPTCHA (ClickFix). Victim manually pastes an obfuscated PowerShell one-liner into Run dialog or Terminal.
  • Payload behavior: Lumma Stealer harvests browser credentials, cookies, crypto wallets, and 2FA tokens; AMOS/MacSync perform equivalent theft on macOS; SectopRAT establishes full remote access with secondary payload staging.
  • C2 communication: Lumma communicates over HTTPS to rotating C2 domains with encrypted/encoded POST exfiltration; SectopRAT maintains persistent encrypted sessions and supports plugin-based tasking.
  • Persistence: Run keys, scheduled tasks, and (on macOS) LaunchAgents/LaunchDaemons.
  • Anti-analysis: Heavy PowerShell obfuscation (base64, string concatenation, AMSI bypass strings), abuse of legitimate Google/Cloudflare infrastructure to defeat domain reputation, and canon/signed-binary sideloading to evade application control.

Void Arachne — ValleyRAT

  • Distribution method: SEO poisoning and malvertising pushing trojanized QN Wallpaper installers to Chinese-speaking users.
  • Payload behavior: Keylogging, clipboard hijacking (cryptocurrency address substitution risk), screenshot capture, file exfiltration, and additional payload retrieval.
  • C2 communication: Custom binary protocol, frequently over non-standard ports, with C2 infrastructure concentrated in APAC hosting; beaconing patterns show periodic check-ins with compressed/encrypted payloads.
  • Persistence: DLL sideloading via the signed QN Wallpaper process; the legitimate application's own autostart entries provide durable persistence under a trusted binary.
  • Anti-analysis: Signed-process execution defeats naive allowlisting; modified wallpaper tool retains full functionality to delay user suspicion; payload decrypted in memory only.

IOC Analysis

The pulses contain 23 file-hash indicators (SHA256 and MD5) for the ClickFix campaign covering Lumma, SectopRAT, AMOS, and MacSync stage payloads, and 3 MD5 hashes for ValleyRAT/QN Wallpaper droppers. Notably, no network IOCs (IPs/domains) are present in these pulses — a direct consequence of both campaigns riding on legitimate infrastructure (Google Sites, Google Ads, OpenAI) where IP/domain blocking is infeasible.

Operationalization guidance for SOC teams:

  1. Hash enforcement: Load all SHA256/MD5 indicators into your EDR blocklists (Defender custom indicators, CrowdStrike custom IOAs, Sentinel threat intelligence). MD5s are collision-prone — treat as hunt-only; enforce blocks on SHA256 values.
  2. Pivot tooling: Submit the SHA256 samples to VirusTotal, MalwareBazaar, and ANY.RUN to pivot to dropped C2 domains, mutexes, and second-stage hashes — the pulse's missing network IOCs live one pivot away.
  3. Behavioral layering: Because infrastructure IOCs are absent, detection must lean on behavior: browser-spawned PowerShell/cmd, unsigned DLL loads under signed processes, and paste-into-Run-dialog telemetry.
  4. Feed management: Ingest the pulses via OTX DirectConnect API into your TIP and set expiry — stealer hashes rotate quickly; weight these IOCs high for 30 days, then demote.

Detection Engineering

YAML
---
title: ClickFix Pattern - Browser Spawns Obfuscated PowerShell
id: 7f3a1c2e-9b4d-4e8a-a1f2-3c5d6e7f8a9b
status: experimental
description: Detects web browsers spawning PowerShell with obfuscation or download cradles, consistent with ClickFix fake-CAPTCHA campaigns delivering Lumma Stealer/SectopRAT via ChatGPT Custom GPT and Google Sites lures.
author: Security Arsenal Threat Intel
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\firefox.exe'
      - '\brave.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
  selection_flags:
    CommandLine|contains:
      - ' -enc'
      - ' -ec'
      - 'EncodedCommand'
      - 'FromBase64String'
      - 'IEX'
      - 'Invoke-Expression'
      - 'DownloadString'
      - 'Start-BitsTransfer'
      - 'hidden'
      - '-w h'
  condition: selection_parent and selection_child and selection_flags
falsepositives:
  - Rare legitimate IT tooling launched from browser portals
level: high
tags:
  - attack.execution
  - attack.t1059.001
  - attack.t1204.002
---
title: User Paste Execution - Run Dialog or Explorer Launches Scripting Engine
id: 8a4b2d3f-1c5e-5f9b-b2a3-4d6e7f8a9b0c
status: experimental
description: Detects explorer.exe or the Run dialog spawning mshta, wscript, or PowerShell with command-line content, a strong ClickFix indicator where the victim pastes a malicious command after a fake Cloudflare CAPTCHA.
author: Security Arsenal Threat Intel
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\explorer.exe'
      - '\rundll32.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\mshta.exe'
      - '\wscript.exe'
      - '\cscript.exe'
  selection_content:
    CommandLine|contains:
      - 'http'
      - 'IEX'
      - ' -enc'
      - 'New-Object'
  condition: selection_parent and selection_child and selection_content
falsepositives:
  - Helpdesk-driven software installs walked through with end users
level: medium
tags:
  - attack.execution
  - attack.t1204
  - attack.t1059
---
title: DLL Sideloading - Unsigned DLL Loaded by Signed Process in User Path
id: 9c5e4a1b-2d6f-4a8c-c3b4-5e7f8a9b0c1d
status: experimental
description: Detects DLL image loads from user-writable or non-standard directories by signed executables, matching ValleyRAT's QN Wallpaper sideloading and canon sideloading used in the ClickFix Lumma/SectopRAT chain.
author: Security Arsenal Threat Intel
logsource:
  category: image_load
  product: windows
detection:
  selection_path:
    ImageLoaded|contains:
      - '\AppData\Local\'
      - '\AppData\Roaming\'
      - '\Users\Public\'
      - '\Temp\'
      - '\Downloads\'
  selection_ext:
    ImageLoaded|endswith: '.dll'
  filter_signed_paths:
    ImageLoaded|contains:
      - '\AppData\Local\Microsoft\'
      - '\AppData\Local\Google\'
      - '\AppData\Local\Programs\'
  condition: selection_path and selection_ext and not filter_signed_paths
falsepositives:
  - Portable applications and developer tooling loading local plugins
level: medium
tags:
  - attack.defense_evasion
  - attack.persistence
  - attack.t1574.002
KQL — Microsoft Sentinel / Defender
// ClickFix + ValleyRAT hunt: browser-spawned scripts, Run-dialog pastes, and sideloaded DLLs
let ClickFixProc = DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where InitiatingProcessFileName in~ ("chrome.exe","msedge.exe","firefox.exe","brave.exe")
| where FileName in~ ("powershell.exe","pwsh.exe","mshta.exe","wscript.exe","cscript.exe","cmd.exe")
| where ProcessCommandLine has_any ("-enc","FromBase64String","IEX","DownloadString","Invoke-Expression","hidden","Start-BitsTransfer")
| project TimeGenerated, DeviceName, AccountName, InitiatingProcessFileName, FileName, ProcessCommandLine, SHA256 = InitiatingProcessSHA256
| extend DetectionType = "BrowserSpawnedScript";
let RunDialogPaste = DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where InitiatingProcessFileName =~ "explorer.exe"
| where FileName in~ ("powershell.exe","mshta.exe")
| where ProcessCommandLine has_any ("http","IEX","New-Object","-enc")
| project TimeGenerated, DeviceName, AccountName, InitiatingProcessFileName, FileName, ProcessCommandLine, SHA256 = InitiatingProcessSHA256
| extend DetectionType = "RunDialogPaste";
let SideLoad = DeviceImageLoadEvents
| where TimeGenerated > ago(7d)
| where FileName endswith ".dll"
| where FolderPath has_any ("\\AppData\\Local\\","\\AppData\\Roaming\\","\\Users\\Public\\","\\Temp\\","\\Downloads\\")
| where FolderPath !has "\\AppData\\Local\\Microsoft\\" and FolderPath !has "\\AppData\\Local\\Google\\"
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, FolderPath, SHA256
| extend DetectionType = "SuspectDllSideload";
union ClickFixProc, RunDialogPaste, SideLoad
| sort by TimeGenerated desc
PowerShell
# Security Arsenal - ClickFix / ValleyRAT / Lumma IOC & Artifact Hunt
# Run as Administrator on suspect endpoints or via EDR remote shell / GPO.

$ErrorActionPreference = 'SilentlyContinue'
$report = @()

# --- 1. Hash sweep of user-writable directories (pulse IOCs) ---
$iocHashes = @(
    '22869e3326fe1de011cd500e666769027126c5c440b76837baf55139f30094e4',
    '0457414c4504b70115798eee9c8384a8bf9e793461ffb2e0661a6dcc6ed4809f',
    '14e3376befd4b7b52de0757b6264da294ac6b0f9e4ff51cb9bc5b19b243fe335',
    '20c7befc174a61117770535e809046c75e93c71284bf1a9c6cd532f55b315f53',
    '278e2f3e2f26c18666b89ef774b4af9ce954e36b2bf54a2392608619245d8c48',
    '3cd1484cc5bf10e22d79784beba58a75d7b126c46efb5e1a85d6aab884447621'
)
$sweepPaths = @("$env:LOCALAPPDATA","$env:APPDATA","$env:PUBLIC","$env:TEMP")
foreach ($p in $sweepPaths) {
    Get-ChildItem $p -Recurse -File -Include *.exe,*.dll,*.ps1,*.bat -Depth 3 |
        ForEach-Object {
            $h = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()
            if ($iocHashes -contains $h) {
                $report += [PSCustomObject]@{Type='IOC_HASH_HIT'; Path=$_.FullName; Detail=$h}
            }
        }
}

# --- 2. Run key persistence (Lumma / SectopRAT) ---
$runKeys = @(
    'HKCU:\Software\Microsoft\Windows\CurrentVersion\Run',
    'HKCU:\Software\Microsoft\Windows\CurrentVersion\RunOnce',
    'HKLM:\Software\Microsoft\Windows\CurrentVersion\Run'
)
foreach ($rk in $runKeys) {
    Get-ItemProperty $rk | ForEach-Object {
        $_.PSObject.Properties | Where-Object {
            $_.Value -match 'powershell|mshta|AppData|Temp|Public' -and
            $_.Name -notmatch '^PS'
        } | ForEach-Object {
            $report += [PSCustomObject]@{Type='RUNKEY_SUSPICIOUS'; Path=$rk; Detail="$($_.Name) = $($_.Value)"}
        }
    }
}

# --- 3. Scheduled tasks executing from user paths ---
Get-ScheduledTask | ForEach-Object {
    $actions = $_.Actions | Out-String
    if ($actions -match 'AppData|Temp|Users\\Public|powershell.*-enc') {
        $report += [PSCustomObject]@{Type='SCHEDTASK_SUSPICIOUS'; Path=$_.TaskName; Detail=$actions.Trim()}
    }
}

# --- 4. QN Wallpaper / ValleyRAT artifacts ---
$qnPaths = @(
    "$env:LOCALAPPDATA\QNWallpaper",
    "$env:APPDATA\QNWallpaper",
    "$env:ProgramFiles\QNWallpaper",
    "${env:ProgramFiles(x86)}\QNWallpaper"
)
foreach ($q in $qnPaths) {
    if (Test-Path $q) {
        Get-ChildItem $q -Recurse -Filter *.dll | ForEach-Object {
            $sig = Get-AuthenticodeSignature $_.FullName
            if ($sig.Status -ne 'Valid') {
                $report += [PSCustomObject]@{Type='VALLEYRAT_UNSIGNED_DLL'; Path=$_.FullName; Detail=$sig.Status}
            }
        }
    }
}

# --- 5. Live network connections from scripting/RAT processes ---
Get-NetTCPConnection -State Established |
    ForEach-Object {
        $proc = Get-Process -Id $_.OwningProcess
        if ($proc.ProcessName -match 'powershell|pwsh|mshta|wscript|cscript|wallpaper') {
            $report += [PSCustomObject]@{Type='NETCONN_SUSPICIOUS'; Path=$proc.Path; Detail="$($_.RemoteAddress):$($_.RemotePort)"}
        }
    }

# --- 6. macOS AMOS/MacSync check (if run via remoting to Macs, use launchctl/launchd dirs) ---

if ($report.Count -gt 0) {
    $report | Format-Table -AutoSize
    $report | Export-Csv ".\ClickFix_ValleyRAT_Hunt_$(Get-Date -Format yyyyMMdd_HHmm).csv" -NoTypeInformation
    Write-Host "[!] $($report.Count) suspicious artifact(s) found. Escalate to IR." -ForegroundColor Red
} else {
    Write-Host "[+] No ClickFix/ValleyRAT artifacts detected on this host." -ForegroundColor Green
}

Response Priorities

Immediate (0–24h):

  • Push all 23 ClickFix SHA256/MD5 hashes and 3 ValleyRAT MD5 hashes to EDR blocklists and network sandbox block feeds.
  • Deploy the Sigma rules and KQL hunt above; prioritize triage of any browser-spawned PowerShell hits in the last 7 days.
  • Enable PowerShell Script Block Logging and Module Logging if not already enforced; capture Sysmon Event ID 7 (image loads) for sideload detection.
  • Search email and web proxy logs for traffic to Google Sites URLs immediately following Google Ads referral clicks.

24 Hours:

  • Lumma Stealer and AMOS are credential and session-token thieves — if any endpoint confirms execution, initiate enterprise-wide forced credential reset for that user's accessible accounts, revoke active sessions and OAuth tokens, and re-enroll MFA. Treat browser-stored credentials as burned.
  • Review IdP (Entra ID/Okta) sign-in logs for anomalous sessions from the affected user within the execution window; stealer logs are monetized within hours on dark web markets.
  • For ValleyRAT confirmations, check clipboard history artifacts and transaction logs — clipboard hijacking targets cryptocurrency transfers.

1 Week:

  • Deploy Constrained Language Mode or WDAC/AppLocker policies blocking user-context PowerShell from launching from browser processes; consider disabling Run dialog paste execution via attack surface reduction where feasible.
  • Restrict unsigned DLL loading in user-writable paths via WDAC DLL rules; inventory all signed third-party software (especially regional tools like QN Wallpaper) and hash-pin allowed plugins.
  • Conduct targeted user-awareness training on ClickFix: no legitimate CAPTCHA will ever ask a user to paste commands into Run, Terminal, or PowerShell.
  • Subscribe to OTX DirectConnect for continuous ingestion of Void Arachne and ClickFix-cluster pulses into the TIP.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.