THREATOPS
THREAT OPSThreat News › I just trusted the security certificate prompt… Beware of the LegionLoader malware being distributed via the ClickFix method

I just trusted the security certificate prompt… Beware of the LegionLoader malware being distributed via the ClickFix method

lowahnlabPublished 2026-09-02

The AhnLab SEcurity intelligence Center (ASEC) recently identified the LegionLoader malware, which is currently being distributed via the ClickFix method. There are two main distribution methods identified so far; both involve tricking users into visiting a malicious URL and then prompting them to directly execute malicious PowerShell commands through a fake Cloudflare CAPTCHA screen.   [&#82

MITRE ATT&CK techniques

Original source: https://asec.ahnlab.com/en/95374/