Known malicious kithighstealer

ClickFix cache smuggling: later-stage servers named by Microsoft — scanned or contacted host

family: clickfix-cache-smuggling-2026-10

Servers used after the pasted command has run, in the ClickFix cache-smuggling campaign reported by Microsoft Threat Intelligence on 2026-10-03. The VBScript taken from the browser cache retrieves a PowerShell stage (v.ps1) from cocojambo[.]us[.]com/alfa; the credential-stealing code injected into timeout.exe retrieves another stage from capsysnet[.]vg and connects to ciliabula[.]cc. Browsed directly on 2026-10-04, cocojambo[.]us[.]com was blocked by its CDN as suspected malware, capsysnet[.]vg redirected to the site of an unrelated, legitimate webmail provider, and ciliabula[.]cc showed a login page.

Anchors

SMQL queryrun
domain:cocojambo.us.com OR domain:*.cocojambo.us.com OR domain:capsysnet.vg OR domain:*.capsysnet.vg OR domain:ciliabula.cc OR domain:*.ciliabula.cc OR contacted_host:cocojambo.us.com OR contacted_host:capsysnet.vg OR contacted_host:ciliabula.cc

Provenance

Added: 2026-10-04 13:07
Matches scans of these exact hostnames and their subdomains, and pages whose browser contacted them. A compromised site showing the lure is not expected to contact them, because the victim's computer fetches these stages after the command runs; this anchor follows the servers themselves. Their IP addresses are not included: they are rented virtual servers and shared hosting that change tenants. capsysnet[.]vg answers with the same redirect to that webmail site as servers publicly labelled CountLoader. One of them is alphastore[.]vg, which SOCRadar's August 2026 report lists as a delivery host of the DOUBLECUP ClickFix service and as a CountLoader server. CountLoader is the loader DOUBLECUP is reported to deliver. Its later stages (PowerShell run in memory, then a Python payload started by a scheduled task through pythonw.exe) resemble Microsoft's description. This is an overlap in infrastructure and behaviour, not a confirmed attribution: Microsoft has not named the operator, the browser-cache technique has been public since 2025, and CountLoader was in use before DOUBLECUP.

Sightings (3)

HostScanScriptMatchWhen
ciliabula.cc668992a2…—query2026-10-04 13:09
capsysnet.vg8baa5a6d…—query2026-10-04 13:09
cocojambo.us.com06806e90…—query2026-10-04 13:09