Velvet Tempest Exploits ClickFix and Legitimate Windows Utilities to Deploy DonutLoader and CastleRAT Malware
Threat actors operating under the moniker Velvet Tempest, also identified as DEV-0504, have been observed employing a sophisticated multi-stage attack chain that leverages the "ClickFix" technique and built-in Windows utilities…






