<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Loader on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/loader/</link><description>Recent content in Loader on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Mon, 16 Jun 2025 17:41:28 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/loader/index.xml" rel="self" type="application/rss+xml"/><item><title>ClickFix Malware Campaigns: BabaDeda &amp; New Loaders</title><link>https://zxcloudsecurity.co.uk/posts/clickfix-campaigns-babadeda-lorem-ipsum-potemkin-malware-loaders/</link><pubDate>Tue, 16 Jun 2026 17:41:28 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/clickfix-campaigns-babadeda-lorem-ipsum-potemkin-malware-loaders/</guid><description>ClickFix campaigns are spreading three new malware loaders targeting education and finance. Learn what cloud security teams should do now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/clickfix-campaigns-expand-malware.html">The Hacker News</a></p>
<hr>
<p>Multiple ClickFix social engineering campaigns are actively distributing three new malware loaders — BabaDeda, Lorem Ipsum, and Potemkin — targeting education and financial sectors. ClickFix tricks users into manually executing malicious commands by presenting fake error messages or software update prompts. The campaigns have been flagged by three independent security vendors, indicating broad and active threat actor interest in this delivery technique.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review and tighten endpoint execution policies to block PowerShell and cmd invocations triggered from browser processes; consider deploying application control rules that prevent users from manually running scripts copied from web pages. Ensure security awareness training explicitly covers ClickFix-style lures, particularly for staff in education and finance verticals.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/clickfix-campaigns-expand-malware.html">ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures</a></p>
]]></content:encoded></item></channel></rss>