Delivering Trojans Via ClickFix Captcha
Essential information
- Published
- 01/04/2025 14:48
- Modified
- 01/04/2025 17:28
- Tags
- 2025-04-01 banking trojan clickfix captcha evasion techniques obfuscation php dropper powershell qbot quakbot social engineering
- Related entities
- 1 intrusion sets (apt), 10 techniques (mitre), 5 malware
Description
A new social engineering technique exploiting ClickFix Captcha has emerged as an effective method for delivering various types of malware, including Quakbot. This technique deceives users and bypasses security measures by utilizing a seemingly harmless captcha. The process involves redirecting users to a ClickFix captcha that tricks them into executing a malicious command on their local machine. The command downloads and executes obfuscated PowerShell scripts, which then retrieve and deploy the actual malware payload. The attackers use sophisticated obfuscation techniques, including fake ZIP files and PHP-based droppers, to evade detection and analysis. This method's success lies in exploiting user trust in captchas and legitimate-looking websites, increasing the likelihood of unknowing malware execution.