Known malicious kithighstealer
ClickFix cache smuggling: later-stage servers named by Microsoft — scanned or contacted host
family: clickfix-cache-smuggling-2026-10
Servers used after the pasted command has run, in the ClickFix cache-smuggling campaign reported by Microsoft Threat Intelligence on 2026-10-03. The VBScript taken from the browser cache retrieves a PowerShell stage (v.ps1) from cocojambo[.]us[.]com/alfa; the credential-stealing code injected into timeout.exe retrieves another stage from capsysnet[.]vg and connects to ciliabula[.]cc. Browsed directly on 2026-10-04, cocojambo[.]us[.]com was blocked by its CDN as suspected malware, capsysnet[.]vg redirected to the site of an unrelated, legitimate webmail provider, and ciliabula[.]cc showed a login page.
Anchors
SMQL queryrun
domain:cocojambo.us.com OR domain:*.cocojambo.us.com OR domain:capsysnet.vg OR domain:*.capsysnet.vg OR domain:ciliabula.cc OR domain:*.ciliabula.cc OR contacted_host:cocojambo.us.com OR contacted_host:capsysnet.vg OR contacted_host:ciliabula.ccProvenance
Added: 2026-10-04 13:07
Matches scans of these exact hostnames and their subdomains, and pages whose browser contacted them. A compromised site showing the lure is not expected to contact them, because the victim's computer fetches these stages after the command runs; this anchor follows the servers themselves. Their IP addresses are not included: they are rented virtual servers and shared hosting that change tenants. capsysnet[.]vg answers with the same redirect to that webmail site as servers publicly labelled CountLoader. One of them is alphastore[.]vg, which SOCRadar's August 2026 report lists as a delivery host of the DOUBLECUP ClickFix service and as a CountLoader server. CountLoader is the loader DOUBLECUP is reported to deliver. Its later stages (PowerShell run in memory, then a Python payload started by a scheduled task through pythonw.exe) resemble Microsoft's description. This is an overlap in infrastructure and behaviour, not a confirmed attribution: Microsoft has not named the operator, the browser-cache technique has been public since 2025, and CountLoader was in use before DOUBLECUP.
References:
- https://x.com/MsftSecIntel/status/2106197481960706155
- https://scanmalware.com/result/06806e90-982c-4b85-8bf2-abc8fe9dd551
- https://scanmalware.com/result/8baa5a6d-7300-427a-8277-bdd0cc85c817
- https://scanmalware.com/result/668992a2-08de-4e9e-b233-71376adc6f7a
- https://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/