%% Generated by tools/shroudcloud_archive.py from article frontmatter. Edits here are overwritten on the next run. %% Execution-chain teardowns, newest first. Each one follows a single intrusion from the first pasted command to the final payload, with the decoded stages, the infrastructure and the indicators. > [!sc-card] [[ClickFix to IronPython]] > ![[image_bank/cards/clickfix_ironpython_execchain_card.png]] > > `2026-08-14` > > A caret-obfuscated finger command that pulls its batch script over TCP/79, renames curl to a .com file, downloads IronPython from GitHub as a fake PDF, and ends in a keylogger injected into explorer. > [!sc-card] [[ClickFix to NetSupport RAT]] > ![[image_bank/cards/clickfix_netsupport_execchain_card.png]] > > `2026-08-13` > > A fixconfig[.]app one-liner into a self-unpacking PowerShell loader that beacons the victim to Telegram, pulls NetSupport RAT out of a PNG, and persists from a hijacked Startup shortcut. > [!sc-card] [[ClickFix to EtherHiding]] > ![[image_bank/cards/clickfix_etherhiding_execchain_card.png]] > > `2026-07-21` > > A single pasted command that ran all the way to a Python RAT reading its C2 off the Ethereum blockchain. Decoding a ClickFix → EtherHiding → Python-loader chain.