Frequency
2
occurrences
First Seen
November 17, 2025
Last Seen
April 30, 2026
Related Threat Clusters
-
Malicious Background Removal Tool Distributes RATs and Infostealers
A new cyber threat identified by Huntress involves a fake background removal website that tricks users into executing malicious commands. Dubbed BackgroundFix, this site masquerades as a free image-editing service,…
3 articles · Updated May 1, 2026 -
Revival of Finger Command in ClickFix Malware Attacks
Threat actors are exploiting the decades-old 'finger' command in new ClickFix malware attacks to execute remote commands on Windows devices. The command, which was historically used to retrieve user information on Unix…
4 articles · Updated November 17, 2025 -
Revival of 'Finger' Command in ClickFix Malware Attacks
Threat actors have reintroduced the decades-old 'finger' command in new ClickFix malware attacks to facilitate remote command execution on Windows devices. The command, originally used for user information retrieval on…
2 articles · Updated November 17, 2025
Recent Intelligence Reports
- ClickFix Removes Your Background but Leaves the Malware — Huntress · April 30, 2026
- New ClickFix attacks reuse ancient 'finger' command — Scworld · November 17, 2025
Related Entities
Malware
Cwe-327 - Use Of A Broken Or Risky Cryptographic Algorithm
CastleLoader
ClickFix
NetSupport Manager RAT
NetSupportRAT
T1027 - Obfuscated Files Or Information
T1055.012 - Process Hollowing
T1059.003 - Windows Command Shell
T1083 - File And Directory Discovery
T1105 - Ingress Tool Transfer
T1574 - Hijack Execution Flow