ClickFix
A Fake Captcha, a Trojanised File Manager, and a Year of IOC C2 Domains
On 7th October our Threat Intelligence pipeline flagged a script from ohhhhhmoney.com injected into compromised WordPress sites. It is a ClickFix kit, and at the end of the chain is a backdoored copy of a real desktop app. Its Command and Control (C2) server moves to a new domain