As users (and detection tools) have gotten better at identifying the signs of a malware infection and savvy enough to avoid ...
All it took was this 2MB tool.
A fake $TEMU crypto airdrop uses the ClickFix trick to make victims run malware themselves and quietly installs a remote-access backdoor.
New ClickFix variant maps WebDAV drive to run trojanized WorkFlowy app, enabling stealth C2 beacon and payload delivery.