Threat Advisory

ClearFake and ClickFix Campaign Delivery Through PowerShell Scripts

Threat: Malicious Campaign
Threat Actor Name: TA571
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have found technique leverages unique tactics to trick users into running PowerShell scripts that install malware. This method, observed in campaigns by TA571, ClearFake, and ClickFix users with a simultaneous problem and solution, prompting them to take action without considering the risk. Despite requiring significant user interaction, social engineering is enough to deceive users into executing malicious commands.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have found technique leverages unique tactics to trick users into running PowerShell scripts that install malware. This method, observed in campaigns by TA571, ClearFake, and ClickFix users with a simultaneous problem and solution, prompting them to take action without considering the risk. Despite requiring significant user interaction, social engineering is enough to deceive users into executing malicious commands.[emaillocker id="1283"]

The technique involves directing users to copy and paste malicious PowerShell scripts, often initiated via malspam or web browser injects. Users encounter a popup suggesting an error occurred while trying to open a document or webpage, followed by instructions to run a PowerShell script. The ClearFake cluster compromises legitimate websites with malicious HTML and JavaScript, leading users to a fake warning overlay instructing them to install a "root certificate." Following these results in a multi-step attack chain involving various PowerShell scripts that ultimately download and execute malware such as Lumma Stealer, Amadey Loader, XMRig crypto miner, and clipboard hijackers. The ClickFix cluster presents victims with a fake browser update error message, leading them to execute PowerShell commands that download and run malware like Vidar Stealer. TA571 employs similar techniques through HTML attachments in email campaigns, leading users to download and execute malware like DarkGate, Matanbuchus, and NetSupport RAT. The scripts often utilize encoding methods like double-Base64 and reverse Base64 to evade detection and exploit the clipboard's inability to be easily inspected by antivirus software.

This attack chains on significant user interaction, exploiting social engineering in fake error messages that appear authoritative and trustworthy. The attack provides both the problem and solution, prompting users to act quickly without considering the risk. The unique and creative nature of these attack chains reflects a broader trend among to adopt varied and innovative methods for malware delivery, including improved social engineering, nested PowerShell scripts, and the use of WebDAV and SMB. Organizations should users to recognize such activities and mitigate the threat.

THREAT PROFILE:

Tactic Technique Id Technique
 Initial Access  T1566 Phishing
Execution T1059 Command and Scripting Interpreter
Defense Evasion T1027 Obfuscated Files or Information
T1055 Process Injection
Credential Access T1110 Brute Force
Exfiltration T1041 Exfiltration Over C2 Channel
T1020 Automated Exfiltration
Impact T1485 Data Destruction
T1486 Data Encrypted for Impact

REFERENCES:

The following reports contain further technical details:

https://www.darkreading.com/remote-workforce/cut-paste-tactics-import-malware

[/emaillocker]
crossmenu