Episode

Picture perfect deception.

Podcast
Research Saturday
Published
Jan 17, 2026
Duration seconds
1217
Processing state
not_requested
Canonical source
https://thecyberwire.com/podcasts/research-saturday/408/notes
Audio
https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW2746686361.mp3?updated=1768584073
JSON
/v1/public/podcasts/research-saturday-1377435/episodes/picture-perfect-deception
Markdown
/podcast/research-saturday-1377435/picture-perfect-deception.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/picture-perfect-deception/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/research-saturday-1377435/picture-perfect-deception.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Today we are joined by Ben Folland, Security Operations Analyst from Huntress, discussing their work on "ClickFix Gets Creative: Malware Buried in Images." This analysis covers a ClickFix campaign that uses fake human verification checks and a realistic Windows Update screen to trick users into manually running malicious commands. The multi-stage attack chain leverages mshta.exe, PowerShell, and .NET loaders, ultimately delivering infostealers like LummaC2 and Rhadamanthys, with payloads hidden inside PNG images using steganography. While technically sophisticated, the campaign hinges on simple user interaction, underscoring the importance of user awareness and controls around command execution. The research can be found here: ClickFix Gets Creative: Malware Buried in Images Learn more about your ad choices. Visit megaphone.fm/adchoices