TrojanClicker malware family
TrojanClicker is a malware family tracked by MalwareAnalyzer by Cyble across 13 publicly analyzed samples. First seen 2026-07-29, most recently 2026-08-10. Observed ATT&CK techniques include T1112, T1105.
Corpus statistics
- Publicly analyzed samples: 13
- First seen: 2026-07-29
- Last seen: 2026-08-10
- Verdicts: malicious 13
- File types: html 8, script 5
ATT&CK techniques used by TrojanClicker
Extracted command-and-control infrastructure
- https://resources.blogblog.com/img/widgets/icon_contactform_cross.gif - 5 samples
- https://www.blogger.com - 5 samples
- https://www.blogger.com/static/v1/v-css/368954415-lightbox_bundle.css - 5 samples
- https://www.blogger.com/static/v1/jsbin/403901366-ieretrofit.js - 4 samples
- https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css - 4 samples
- https://www.blogger.com/rpc_relay.html - 2 samples
- https://www.blogger.com/static/v1/widgets/1394523530-widget_css_bundle.css - 2 samples
- https://www.blogger.com/static/v1/widgets/204402360-widget_css_bundle.css - 2 samples
- https://www.blogger.com/unvisited-link- - 2 samples
- http://1.bp.blogspot.com/-XwCYgb62Rso/UIxzH1ovo3I/AAAAAAAABMU/F2_Cgdj99f4/s748/headerrrr.png - 1 sample
- http://1.bp.blogspot.com/-gA9ZfIdus80/UKYVziljQ6I/AAAAAAAAASY/7qRP4nbrMMg/s1600/sprite.png - 1 sample
- http://1.bp.blogspot.com/-tL3eG-fGrNY/Ubms_CNXmqI/AAAAAAAAAIg/rCK1aY6w4ug/s320/Overseas-Talent.jpg - 1 sample
- http://1.bp.blogspot.com/_0Ch8jB3poYo/TUyZewfTSBI/AAAAAAAABYw/vbNUjitvPR8/s200/GAST.bmp - 1 sample
- http://1.bp.blogspot.com/_0Ch8jB3poYo/TUyZewfTSBI/AAAAAAAABYw/vbNUjitvPR8/s72-c/GAST.bmp - 1 sample
- http://3.bp.blogspot.com/-IMVKlRJsPPU/UMsVKwO7MYI/AAAAAAAABzI/IXvG053DEko/s1600/loading1.gif - 1 sample
- http://3.bp.blogspot.com/-KUBLkpn5-hk/UbS9Iu9WH4I/AAAAAAAAACc/4QssLKsDo-g/s1600/logo_96.png - 1 sample
- http://3.bp.blogspot.com/-_kxlZJzTg6M/UHs7QeVo41I/AAAAAAAAAkE/pyBd66qH5jA/s400/tipico.jpg - 1 sample
- http://3.bp.blogspot.com/-_kxlZJzTg6M/UHs7QeVo41I/AAAAAAAAAkE/pyBd66qH5jA/w1200-h630-p-k-no-nu/tipico.jpg - 1 sample
- http://3.bp.blogspot.com/-tQxshKVrEiA/UKYWBCJuWTI/AAAAAAAAASg/KkVht2Z3sSA/s1600/sprite2.png);background-position:0 - 1 sample
- http://3.bp.blogspot.com/-vWFjzucVYiU/UmZthxhX-6I/AAAAAAAAAIE/2wkTKLZ5XKI/s1600/logo%2BFAGK.jpg - 1 sample
Recent TrojanClicker samples
- 5ad6e10a1d13799c50bad7d093bfc646f0e27ae95773ae1bdbf5ef8f33732b2b - malicious (2026-08-10)
- 71885e3d048f4920d1a0bf9576c52f5c15998dc41f1399050e3d861c9bcf9c6f - malicious (2026-08-10)
- 8f19349c49b34ec07333ef96cf63d2729ec31fc0590ef3b941b80e8d31f41713 - malicious (2026-08-09)
- 8f157704a6b5a0508aa8918a386c0fece35705cbd7c2865d2478aba1e9e9f48d - malicious (2026-08-09)
- 8f18392b10efd1a270e7be5944268b2e49d10aaa771d6bb9900a221f871dcace - malicious (2026-08-09)
- 8f16c04031b84ebb56995c441eee326b932ee5952dcb7e3dd843a465e5fa7d61 - malicious (2026-08-08)
- 8857dd3b338dd72313b4f2c1cf0613827f72f77569b0b2a3a04860587acd234a - malicious (2026-08-05)
- 885393d731e2cb2c4a20981013b99c94d53a35f8b22b5acf13f77de91d37d77a - malicious (2026-08-04)
- 5f7852136b92cb1f8c94876d6bd46d839fc1ce381e6d265d5ab259e0aa07ab43 - malicious (2026-08-04)
- 8851a2e0995460e7866dd751a160fb168f0738ea94c20e4bab7198f27082d9b8 - malicious (2026-08-03)
- 885867d4db307ead4c418f8210fb20d22bb1903f0888139460b52f0bead51e91 - malicious (2026-07-29)
- 635f053c9728ee521efa341f7a8d6bd4192c950843338417b5437205826c5f66 - malicious (2026-07-29)
- fe6772d247bfc9d2ae713e73177f7e3ff7bebe14eaf82b87be88b3ab10fa0843 - malicious (2026-07-29)
Frequently asked about TrojanClicker
- What is TrojanClicker?
- TrojanClicker is a malware family tracked by MalwareAnalyzer by Cyble across 13 publicly analyzed samples. First seen 2026-07-29, most recently 2026-08-10. Observed ATT&CK techniques include T1112, T1105.
- How many TrojanClicker samples have been analyzed?
- MalwareAnalyzer by Cyble holds 13 publicly analyzed samples attributed to TrojanClicker, first seen 2026-07-29 and most recently 2026-08-10. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does TrojanClicker use?
- Across our TrojanClicker samples the most frequently observed techniques are T1112 (5), T1105 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does TrojanClicker use?
- TrojanClicker samples in this corpus are distributed as html (8), script (5).
- Does TrojanClicker use command-and-control infrastructure?
- Yes. 50 distinct command-and-control indicators have been extracted from TrojanClicker samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is TrojanClicker malicious?
- 13 of 13 analyzed TrojanClicker samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends