ClickFix – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Fri, 23 May 2025 14:40:00 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 ClickFix – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 TikTok videos now push infostealer malware in ClickFix attacks https://earlybirdsinvest.com/tiktok-videos-now-push-infostealer-malware-in-clickfix-attacks/ https://earlybirdsinvest.com/tiktok-videos-now-push-infostealer-malware-in-clickfix-attacks/#respond Fri, 23 May 2025 14:40:00 +0000 https://earlybirdsinvest.com/tiktok-videos-now-push-infostealer-malware-in-clickfix-attacks/

TikTok

Cybercriminals are using TikTok videos to trick users into infecting themselves with Vidar and StealC information-stealing malware in ClickFix attacks.

As Trend Micro recently discovered, the threat actors behind this TikTok social engineering campaign are using videos likely generated using AI that ask viewers to run commands claiming to activate Windows and Microsoft Office, as well as premium features in various legitimate software like CapCut and Spotify.

“This attack uses videos (possibly AI-generated) to instruct users to execute PowerShell commands, which are disguised as software activation steps. TikTok’s algorithmic reach increases the likelihood of widespread exposure, with one video reaching more than half a million views,” Trend Micro said.

“The videos are highly similar, with only minor differences in camera angles and the download URLs used by PowerShell to fetch the payload,” it added.

“These suggest that the videos were likely created through automation. The instructional voice also appears AI-generated, reinforcing the likelihood that AI tools are being used to produce these videos.”

One of the videos claiming to provide instructions on how to “boost your Spotify experience instantly,” has reached almost 500,000 views, with over 20,000 likes and more than 100 comments.

TikTok ClickFix video
TikTok ClickFix video (Trend Micro)

​In the video, the attackers prompt viewers to run a PowerShell command that will instead download and execute a remote script from hxxps://allaivo[.]me/spotify that installs Vidar or StealC information-stealing malware, launching it as a hidden process with elevated permissions.

After being deployed, Vidar can take desktop screenshots and steal credentials, credit cards, cookies, cryptocurrency wallets, text files, and Authy 2FA authenticator databases.

Stealc can also harvest a wide range of sensitive information from infected computers as it targets dozens of web browsers and cryptocurrency wallets.

After the device is compromised, the script will download a second PowerShell script payload from hxxps://amssh[.]co/script[.]ps1 that will add a registry key to launch at startup automatically.

Attack flow
Attack flow (Trend Micro)

​What is ClickFix?

ClickFix is a tactic where attackers employ fake errors or verification systems, such as CAPTCHA prompts, to trick potential targets into running malicious scripts to download and install malware on their devices.

While generally targeting Windows users through PowerShell commands, ClickFix has also been adopted in attacks against macOS and Linux users.

State-sponsored threat groups have also hacked their targets in similar attacks, with APT28 and ColdRiver (Russia), Kimsuky (North Korea), and MuddyWater (Iran) having all used these tactics in espionage campaigns in recent months.

This is not the first time TikTok videos were used to push malware, with cybercriminals capitalizing on a trending TikTok challenge named ‘Invisible Challenge’ to infect thousands with a fake app that installed WASP Stealer (Discord Token Grabber) malware.

The malware was pushed through videos that received over a million views shortly after being posted and can steal Discord accounts, passwords, credit cards, and cryptocurrency wallets.

In recent years, scammers have also been flooding TikTok with fake cryptocurrency giveaways, almost all using Elon Musk, Tesla, or SpaceX themes.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/tiktok-videos-now-push-infostealer-malware-in-clickfix-attacks/feed/ 0 37868
Hackers now testing ClickFix attacks against Linux targets https://earlybirdsinvest.com/hackers-now-testing-clickfix-attacks-against-linux-targets/ https://earlybirdsinvest.com/hackers-now-testing-clickfix-attacks-against-linux-targets/#respond Mon, 12 May 2025 20:23:25 +0000 https://earlybirdsinvest.com/hackers-now-testing-clickfix-attacks-against-linux-targets/

Linux

A new campaign employing ClickFix attacks has been spotted targeting both Windows and Linux systems using instructions that make infections on either operating system possible.

ClickFix is a social engineering tactic where fake verification systems or application errors are used to trick website visitors into running console commands that install malware.

These attacks have traditionally targeted Windows systems, prompting targets to execute PowerShell scripts from the Windows Run command, resulting in info-stealer malware infections and even ransomware.

However, a 2024 campaign using bogus Google Meet errors also targeted macOS users.

ClickFix targeting Linux users

A more recent campaign spotted by Hunt.io researchers last week is among the first to adapt this social engineering technique for Linux systems.

The attack, which is attributed to the Pakistan-linked threat group APT36 (aka “Transparent Tribe”), utilizes a website that impersonates India’s Ministry of Defence with a link to an allegedly official press release.

Malicious website mimicking India's Ministry of Defence
Malicious website mimicking India’s Ministry of Defence
Source: Hunt.io

When visitors click on this website link, they are profiled by the platform to determine their operating system, and then redirected to the correct attack flow.

On Windows, victims are served a full-screen page warning them of limited content usage rights. Clicking on ‘Continue’ triggers JavaScript that copies a malicious MSHTA command to the victim’s clipboard, who is instructed to paste and execute it on the Windows terminal.

This launches a .NET-based loader which connects to the attacker’s address, while the user sees a decoy PDF file to make everything appear legitimate and as expected.

On Linux, victims are redirected to a CAPTCHA page that copies a shell command to their clipboard when clicking the “I’m not a robot button.”

The victim is then guided to press ALT+F2 to open a Linux run dialog, paste the command into it, and then press Enter to execute it.

Instructions for Linux users
Instructions for Linux users
Source: Hunt.io

The command drops the ‘mapeal.sh’ payload on the target’s system, which, according to Hunt.io, does not perform any malicious actions in its current version, limited to fetching a JPEG image from the attacker’s server.

Linux ClickFix script
Linux ClickFix script
Source: BleepingComputer

“The script downloads a JPEG image from the same trade4wealth[.]in directory and opens it in the background,” explains Hunt.io.

“No additional activity, such as persistence mechanisms, lateral movement, or outbound communication, was observed during execution.”

However, it is possible that APT36 is currently experimenting to determine the effectiveness of the Linux infection chain, as they would just need to swap out the image for a shell script to install malware or perform other malicious activity.

The adaptation of ClickFix to carry out attacks on Linux is another testament to its effectiveness, as the attack type has now been used against all three major desktop OS platforms.

As a general policy, users should not copy and paste any commands into Run dialogs without knowing exactly what the command does. Doing so only increases the risk of a malware infection and theft of sensitive data.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/hackers-now-testing-clickfix-attacks-against-linux-targets/feed/ 0 35853
Interlock ransomware gang pushes fake IT tools in ClickFix attacks https://earlybirdsinvest.com/interlock-ransomware-gang-pushes-fake-it-tools-in-clickfix-attacks/ https://earlybirdsinvest.com/interlock-ransomware-gang-pushes-fake-it-tools-in-clickfix-attacks/#respond Fri, 18 Apr 2025 19:56:08 +0000 https://earlybirdsinvest.com/interlock-ransomware-gang-pushes-fake-it-tools-in-clickfix-attacks/

Hacker

The Interlock ransomware gang now uses ClickFix attacks that impersonate IT tools to breach corporate networks and deploy file-encrypting malware on devices.

ClickFix is a social engineering tactic where victims are tricked into executing dangerous PowerShell commands on their systems to supposedly fix an error or verify themselves, resulting in the installation of malware.

Though this isn’t the first time ClickFix has been linked to ransomware infections, confirmation about Interlock shows an increasing trend in these types of threat actors utilizing the tactic.

Interlock is a ransomware operation launched in late September 2024, targeting FreeBSD servers and Windows systems.

Interlock is not believed to operate as a ransomware-as-a-service model. Still, it maintains a data leak portal on the dark web to increase pressure on victims, demanding payments ranging from hundreds of thousands of dollars to millions.

From ClickFix to ransomware

In the past, Interlock utilized fake browser and VPN client updates to install malware and breach networks.

According to Sekoia researchers, the Interlock ransomware gang began utilizing ClickFix attacks in January 2025.

Interlock used at least four URLs to host fake CAPTCHA prompts that tell visitors to execute a command on their computer to verify themselves and download a promoted tool.

The researchers say they detected the malicious captcha on four different sites, mimicking Microsoft or Advanced IP Scanner portals:

  • microsoft-msteams[.]com/additional-check.html
  • microstteams[.]com/additional-check.html
  • ecologilives[.]com/additional-check.html
  • advanceipscaner[.]com/additional-check.html

However, only the site impersonating Advanced IP Scanner, a popular IP scanning tool commonly used by IT staff, led to downloading a malicious installer.

Page hosting Interlock's ClickFix bait
Page hosting Interlock’s ClickFix bait
Source: Sekoia

Clicking the ‘Fix it’ button copies the malicious PowerShell command to the victim’s clipboard. If executed in a command prompt or Windows Run dialog, it will download a 36MB PyInstaller payload.

At the same time, the legitimate AdvanceIPScanner website opens in a browser window to reduce suspicion.

The malicious payload installs a legitimate copy of the software it pretends to be and simultaneously executes an embedded PowerShell script that runs in a hidden window.

This script registers a Run key in Windows Registry for persistence and then collects and exfiltrates system info including OS version, user privilege level, running processes, and available drives.

Sekoia has observed the command and control (C2) responding with various payloads, including LummaStealer, BerserkStealer, keyloggers, and the Interlock RAT.

The latter is a simple trojan that can be dynamically configured, supporting file exfiltration, shell command execution, and running malicious DLLs.

Commands Interlock RAT supports
Commands Interlock RAT supports
Source: Sekoia

After the initial compromise and RAT deployment, Interlock operators used stolen credentials to move laterally via RDP, while Sekoia also saw PuTTY, AnyDesk, and LogMeIn used in some attacks.

The last step before the ransomware execution is data exfiltration, with the stolen files uploaded to attacker-controlled Azure Blobs.

The Windows variant of Interlock is set (via a scheduled task) to run daily at 08:00 PM, but thanks to file extension-based filtering, this doesn’t cause multiple layers of encryption but serves as a redundancy measure.

Sekoia also reports that the ransom note has evolved, too, with the latest versions focusing more on the legal aspect of the data breach and the regulatory consequences if stolen data is made public.

Interlock's latest ransom note
Interlock’s latest ransom note
Source: BleepingComputer

ClickFix attacks have now been adopted by a wide range of threat actors, including other ransomware gangs and North Korean hackers.

Last month, Sekoia discovered that the infamous Lazarus North Korean hacking group was using ClickFix attacks targeting job seekers in the cryptocurrency industry.

]]>
https://earlybirdsinvest.com/interlock-ransomware-gang-pushes-fake-it-tools-in-clickfix-attacks/feed/ 0 31552
Lazarus Group Evolves Tactics to Target CeFi Job Seekers with ‘ClickFix’ Malware https://earlybirdsinvest.com/lazarus-group-evolves-tactics-to-target-cefi-job-seekers-with-clickfix-malware/ https://earlybirdsinvest.com/lazarus-group-evolves-tactics-to-target-cefi-job-seekers-with-clickfix-malware/#respond Sun, 06 Apr 2025 02:51:56 +0000 https://earlybirdsinvest.com/lazarus-group-evolves-tactics-to-target-cefi-job-seekers-with-clickfix-malware/

A recent cybersecurity report by Sekoia revealed an evolving threat posed by the Lazarus Group, the notorious North Korea-linked hacking group. It is now leveraging a tactic known as “ClickFix” to target job seekers in the cryptocurrency sector, particularly within centralized finance (CeFi).

This approach marks an adaptation of the group’s earlier “Contagious Interview” campaign, which was previously aimed at developers and engineers in artificial intelligence and crypto-related roles.

Lazarus Exploits Crypto Hiring

In the newly observed campaign, Lazarus has shifted its focus to non-technical professionals, such as marketing and business development personnel, by impersonating major crypto firms like Coinbase, KuCoin, Kraken, and even stablecoin issuer Tether.

The attackers build fraudulent websites mimicking job application portals and lure candidates with fake interview invitations. These sites often include realistic application forms and even requests for video introductions, fostering a sense of legitimacy.

However, when a user attempts to record a video, they are shown a fabricated error message, which typically suggests a webcam or driver malfunction. The page then prompts the user to run PowerShell commands under the guise of troubleshooting, thereby triggering the malware download.

This ClickFix method, though relatively new, is becoming more prevalent due to its psychological simplicity – since users believe they are resolving a technical issue, and not executing malicious code. According to Sekoia, the campaign draws on materials from 184 fake interview invitations, referencing at least 14 prominent companies to bolster credibility.

As such, the latest tactic demonstrates Lazarus’s growing sophistication in social engineering and its ability to exploit the professional aspirations of individuals in the competitive crypto job market. Interestingly, this shift also suggests that the group is expanding its targeting criteria by aiming not just at those with access to code or infrastructure but also at those who might handle sensitive internal data or be in a position to facilitate breaches inadvertently.

Despite the emergence of ClickFix, Sekoia reported that the original Contagious Interview campaign remains active. This parallel deployment of strategies suggests that North Korea’s state-sponsored collective may be testing their relative effectiveness or tailoring tactics to different target demographics. In both cases, the campaigns share a consistent goal – delivering info-stealing malware through trusted channels and manipulating victims into self-infection.

Lazarus Behind Bybit Hack

The Federal Bureau of Investigation (FBI) officially attributed the $1.5 billion attack on Bybit to the Lazarus Group. Hackers targeting the crypto exchange employed fake job offers to trick staff into installing tainted trading software known as “TraderTraitor.”

Although crafted to look authentic through cross-platform JavaScript and Node.js development, the applications embedded malware designed to steal private keys and execute illicit transactions on the blockchain.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/lazarus-group-evolves-tactics-to-target-cefi-job-seekers-with-clickfix-malware/feed/ 0 29255