Threat Advisory

ClickFix Malware Executes Through Fake CAPTCHA

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A new ClickFix campaign is turning a web safety check into a route for malware. The campaign starts after a victim reaches an altered website, where they see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and press Enter.

The instruction looks simple, but it makes the victim run the attacker’s command. The main script is placed on the computer before that step, hiding in the browser cache rather than arriving as an obvious download. Microsoft Threat Intelligence identified the activity in a cluster of compromised websites.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A new ClickFix campaign is turning a web safety check into a route for malware. The campaign starts after a victim reaches an altered website, where they see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and press Enter.

The instruction looks simple, but it makes the victim run the attacker’s command. The main script is placed on the computer before that step, hiding in the browser cache rather than arriving as an obvious download. Microsoft Threat Intelligence identified the activity in a cluster of compromised websites.[emaillocker id="1283"]

The attack starts after a victim reaches an altered website. A fake verification or repair panel asks them to use Win+R, paste material from the clipboard, and run it. Behind the page, the VBScript payload has already been stored in the browser profile cache as a PNG-like resource.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.001 Command and Scripting Interpreter PowerShell
Execution T1059.005 Command and Scripting Interpreter Visual Basic
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Execution E1204 User Execution
Persistence F0012 Registry Run Keys / Startup Folder
Command & Control E1105 Ingress Tool Transfer
Command & Control B0030 C2 Communication
Discovery E1083 File and Directory Discovery
Anti-Static Analysis E1027 Obfuscated Files or Information
Anti-Static Analysis B0032 Executable Code Obfuscation

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu