By John Hammond, Alden Schmidt, Lindsey Welch During the past fifteen business days, Huntress analysts have observed increased threat activity involving several notable techniques. One case involved a malicious AnyDesk installer, which initially mimicked a standard ClickFix attack through a fake Cloudflare verification page but then utilized Windows File Explorer and an MSI package masked as a PDF to deploy MetaStealer malware. Additionally, two incidents involving the Cephalus ransomware variant were detected. This ransomware distinguishes itself by employing DLL sideloading through a legitimate SentinelOne executable, SentinelBrowserNativeHost.exe, to launch the payload. These recent findings highlight the ongoing evolution in threat actor tradecraft, combining established social engineering methods with more technically advanced infection chains and evasive deployment strategies. ClickFix attacks have been ticking up for over a year now, as attackers find success in tricking users into executing malicious code on their computers using CAPTCHA-based lures. We’ve seen quite a bit of these types of attacks on our end, but we’ve also seen threat actors adopting ClickFix-esque techniques in attacks that don’t follow the exact ClickFix playbook. Recently, our very own John Hammond received an email from someone who had come across a fake AnyDesk installer while searching for the AnyDesk remote tool. While early indicators of the attack look like it would turn into another Click...
From ClickFix to MetaStealer: Dissecting Evolving Threat Actor Techniques
BleepingComputer
·Sponsored by Huntress
·Published Sep 17, 2025
·Updated
Affected Software
1 affected component
SentinelOne SentinelBrowserNativeHost
Frequently Asked Questions
1
What are the main techniques discussed in the article regarding evolving threat actor tactics?
The article highlights new malicious tactics such as the use of fake installers and the MetaStealer malware.
2
What specific malware is mentioned as part of the evolving threat landscape?
The article mentions MetaStealer as a key malware variant currently being exploited by threat actors.
3
What software is primarily affected by the described threat activities?
The software impacted by these threat techniques includes SentinelOne SentinelBrowserNativeHost.
4
Who conducted the analysis on the increasing threat activity?
The analysis was conducted by Huntress analysts.
5
What initial attack method did the malicious AnyDesk installer mimic?
The malicious AnyDesk installer initially mimicked a standard ClickFix attack.