EXECUTIVE SUMMARY
Researchers have found technique leverages unique tactics to trick users into running PowerShell scripts that install malware. This method, observed in campaigns by TA571, ClearFake, and ClickFix users with a simultaneous problem and solution, prompting them to take action without considering the risk. Despite requiring significant user interaction, social engineering is enough to deceive users into executing malicious commands.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Researchers have found technique leverages unique tactics to trick users into running PowerShell scripts that install malware. This method, observed in campaigns by TA571, ClearFake, and ClickFix users with a simultaneous problem and solution, prompting them to take action without considering the risk. Despite requiring significant user interaction, social engineering is enough to deceive users into executing malicious commands.[emaillocker id="1283"]
The technique involves directing users to copy and paste malicious PowerShell scripts, often initiated via malspam or web browser injects. Users encounter a popup suggesting an error occurred while trying to open a document or webpage, followed by instructions to run a PowerShell script. The ClearFake cluster compromises legitimate websites with malicious HTML and JavaScript, leading users to a fake warning overlay instructing them to install a "root certificate." Following these results in a multi-step attack chain involving various PowerShell scripts that ultimately download and execute malware such as Lumma Stealer, Amadey Loader, XMRig crypto miner, and clipboard hijackers. The ClickFix cluster presents victims with a fake browser update error message, leading them to execute PowerShell commands that download and run malware like Vidar Stealer. TA571 employs similar techniques through HTML attachments in email campaigns, leading users to download and execute malware like DarkGate, Matanbuchus, and NetSupport RAT. The scripts often utilize encoding methods like double-Base64 and reverse Base64 to evade detection and exploit the clipboard's inability to be easily inspected by antivirus software.
This attack chains on significant user interaction, exploiting social engineering in fake error messages that appear authoritative and trustworthy. The attack provides both the problem and solution, prompting users to act quickly without considering the risk. The unique and creative nature of these attack chains reflects a broader trend among to adopt varied and innovative methods for malware delivery, including improved social engineering, nested PowerShell scripts, and the use of WebDAV and SMB. Organizations should users to recognize such activities and mitigate the threat.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1055 | Process Injection | |
| Credential Access | T1110 | Brute Force |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| T1020 | Automated Exfiltration | |
| Impact | T1485 | Data Destruction |
| T1486 | Data Encrypted for Impact |
REFERENCES:
The following reports contain further technical details:
https://www.darkreading.com/remote-workforce/cut-paste-tactics-import-malware
[/emaillocker]