A newly discovered variant of the ClickFix malware masquerades as a critical Windows Update, using a fake full-screen update prompt to trick users into pasting a malicious command that grants attackers administrative access. Huntress researchers found that the malware leverages hidden code in PNG pixel data to deploy powerful infostealers like Rhadamanthys and LummaC2, targeting credentials, financial data, and crypto wallets primarily via booby-trapped adult websites.