ClickFix attackers hide malware payloads in browser caches

First reported by Cyber Security News at · Updated · 4 sources

Compromised websites use fake verification prompts to trick visitors into executing malicious commands. Cyber Security News says victims are instructed to paste text into the Windows Run dialog and press Enter. The Hacker News reports that Microsoft identified scripts disguised as PNG files and loaded into browser caches before execution.

  • The Record reports over 100 websites compromised in Ukraine to spread Lunex malware.
  • Dark Reading also reports payload concealment using DNS TXT records.

Covered by 4 publishers within 32 hours of the first report.

Reporting4

Cyber Security News ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache · Tushar Subhra Dutta
The Hacker News ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits · info@thehackernews.com (The Hacker News)
Dark Reading ClickFix Attacks Evolve to Better Hide Malicious Payloads · Alexander Culafi

Related

Topics Microsoft