<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Houdin.io blog</title>
		<link>https://houdin.io/blog</link>
		<description>Threat intelligence and research from the Houdin team.</description>
		<language>en</language>
		<atom:link href="https://houdin.io/blog/rss.xml" rel="self" type="application/rss+xml" />
		<item>
			<title>Detecting ClickFix infrastructure before it goes live</title>
			<link>https://houdin.io/blog/detecting-clickfix-infrastructure-before-it-goes-live</link>
			<guid isPermaLink="true">https://houdin.io/blog/detecting-clickfix-infrastructure-before-it-goes-live</guid>
			<pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
			<description>In this article we point out weaknesses in a live ClickFix operator's infrastructure. We showcase a method to preemptively detect threats by monitoring certain points of it.</description>
			<category>clickfix</category>
			<category>threat-hunting</category>
			<category>dead-drop-resolver</category>
			<category>etherhiding</category>
		</item>
	</channel>
</rss>
