216.73.216.6

Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape

· Published 18/11/2024 12:47 · Modified 18/11/2024 17:33

Export JSON

Essential information

Published
18/11/2024 12:47
Modified
18/11/2024 17:33
Tags
2024-11-18 asyncrat brute ratel c4 clickfix cybersecurity danabot darkgate latrodectus lucky volunteer lumma stealer malware delivery netsupport phishing powershell recaptcha phish social engineering threat actors threat landscape xworm
Related entities
10 techniques (mitre), 9 malware, 5 others

Description

Proofpoint researchers have identified a surge in the technique across the . This technique uses dialogue boxes with fake error messages to trick users into copying, pasting, and running malicious content on their computers. Multiple are employing through compromised websites, documents, HTML attachments, and malicious URLs. Recent campaigns have included GitHub security vulnerability notifications, Swiss e-commerce marketplace impersonations, fake software updates, and ChatGPT-themed malvertising. The technique has been observed delivering various malware, including , , , , and . The popularity of is attributed to its effectiveness in bypassing security protections by exploiting users' desire to be helpful and independent.

External references