Threat Advisory

ClickFix Malicious Campaign Uses Fake Travel Sites to Deliver Malicious JavaScript Payloads

Threat: Malicious Campaign
Targeted Region: Global
Targeted Sector: Technology & IT, Retail & E-Commerce
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A threat campaign, dubbed ClickFix, has been observed leveraging social engineering tactics and obfuscated JavaScript payloads to infiltrate targeted environments. The campaign exploits the appearance of legitimate websites and tools to deceive users into executing malicious scripts. It monitors endpoint activity and DNS traffic have identified consistent patterns and behaviors associated with this operation, prompting deeper investigation and the development of high-fidelity detection mechanisms to respond rapidly to emerging threats.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A threat campaign, dubbed ClickFix, has been observed leveraging social engineering tactics and obfuscated JavaScript payloads to infiltrate targeted environments. The campaign exploits the appearance of legitimate websites and tools to deceive users into executing malicious scripts. It monitors endpoint activity and DNS traffic have identified consistent patterns and behaviors associated with this operation, prompting deeper investigation and the development of high-fidelity detection mechanisms to respond rapidly to emerging threats.[emaillocker id="1283"]

The attack chain begins with a command-line execution linked to a suspicious domain that initially masquerades as a benign travel webpage. Upon interaction, a JavaScript file is loaded, containing obfuscated code designed to fingerprint the users device. If the visitor matches targeted criteria, the script generates a unique 8-digit identifier appended to the URL, initiating the download of a secondary script the actual payload. Tools such as Joes Sandbox were used for in-depth file behavior analysis, revealing the creation of additional suspicious artifacts. Historical detection data was queried, identifying similar patterns across multiple customer environments. File hashes were subsequently added to the endpoint blocklist to prevent further compromise. In cases where static analysis was needed, external site scanners were used to retrieve source code, redirects, and network behaviors for further inspection.

ClickFix exemplifies the increasing of modern phishing and social engineering threats, using tailored scripts and obfuscated delivery mechanisms to bypass traditional security controls. Proactive detection rules, custom alarms, and integrated threat intelligence are essential for reducing response time and limiting the impact of such campaigns. It is encouraged to leverage comprehensive endpoint visibility, open threat exchanges, and automated alerting systems to stay ahead of these evolving threats.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial Access T1189 Drive-by Compromise
Execution T1059.007 Command and Scripting Interpreter JavaScript
Collection T1560.001 Archive Collected Data Archive via Utility
Command and Control T1105 Ingress Tool Transfer
T1071.001 Application Layer Protocol Web Protocols

 

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu