Skip to content

Threat research

Blog

Investigations, infrastructure analysis, and SOC tradecraft from the Houdin team. Follow along via RSS.

16 min read

Detecting ClickFix infrastructure before it goes live

In this article we point out weaknesses in a live ClickFix operator's infrastructure. We showcase a method to preemptively detect threats by monitoring certain points of it.

clickfixthreat-huntingdead-drop-resolveretherhiding