Sicuranext Blog
  • Home
  • WAAP
  • SOC
  • PWNPress
  • AI
Sign in Subscribe

Simone Fasolis

One Paste to Rule Them All: Inside a ClickFix → EtherHiding → GULoader Intrusion

One Paste to Rule Them All: Inside a ClickFix → EtherHiding → GULoader Intrusion

A real-world ClickFix intrusion observed from both sandbox and endpoint telemetry, revealing the complete attack path from a compromised WordPress site to a blocked GULoader execution, including a full process creation call stack from the Windows Run dialog to the kernel. Preamble In April 2026, we responded to an endpoint
15 Jun 2026 12 min read
Page 1 of 1
Sicuranext Blog © 2026
  • Sign up
  • Home
  • WAAP
  • PWNPress
  • SicuraNext
Powered by Ghost