Research & KnowledgeEvent: August 31, 2026
Amuneth researchers discovered a new and surprising execution technique within recent ClearFake activities involving a payload that acts as a legitimate Windows Network Diagnostics Utility but instead is a PowerShell-loader forcing 32-bit SysWOW64 PowerShell execution and a handoff of stdin to memory.
Published
Signal category
Research & Knowledge
Quote
“Onderzoekers van Amuneth hebben een nieuwe en opvallende uitvoeringstechniek aangetroffen binnen recente ClearFake-activiteit.”
— Erik Westhovens 🔑|Amuneth team
Company
- Industry
- Computer and Network Security
- Company size
- 2 employees