<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

ClickFix Attacks Are Getting Sneakier About Hiding Their Payloads

ClickFix evolves to evade detection, with campaigns using DNS records and browser cache to deliver malicious payloads.
Content Team

ClickFix, the social engineering trick that fools users into pasting malicious commands into PowerShell, Windows Run, or the macOS Terminal, is evolving to dodge detection. Two new campaigns show attackers rebuilding the moment where a pasted command turns into a payload.

Flare researcher Assaf Morag detailed a campaign spreading CrocoRat — a remote access Trojan and crypto stealer. The victim still pastes a command from the clipboard, but that command now queries a DNS TXT record on an attacker-controlled server, and the record hands back the next PowerShell instruction. The next stage never touches the clipboard, so defenders have fewer forensics to work with.

Flare also found an unexecuted Python launcher in the package, built to choose its payload by environment: a quiet, persistent foothold on systems that look corporate, and the full RAT plus credential and crypto stealers on systems that look personal. The operator appears to be limiting theft on corporate targets to avoid tripping detection.

Microsoft Threat Intelligence flagged a separate cluster of compromised websites that pre-fetch a script into the browser cache, disguised as a PNG, before the fake prompt ever appears. That hides the payload and gets around the Run dialog's character limit. Morag's advice goes after the step itself: alert on clipboard-to-Run patterns, harden PowerShell script-block logging, stop interpreters running from writable directories, and train users on the tells — fake CAPTCHAs, press-Windows+R prompts, and verification-failed screens

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo