ClickFix Attacks Are Getting Sneakier About Hiding Their Payloads
Want more insights like this?
ClickFix, the social engineering trick that fools users into pasting malicious commands into PowerShell, Windows Run, or the macOS Terminal, is evolving to dodge detection. Two new campaigns show attackers rebuilding the moment where a pasted command turns into a payload.
Flare researcher Assaf Morag detailed a campaign spreading CrocoRat — a remote access Trojan and crypto stealer. The victim still pastes a command from the clipboard, but that command now queries a DNS TXT record on an attacker-controlled server, and the record hands back the next PowerShell instruction. The next stage never touches the clipboard, so defenders have fewer forensics to work with.
Flare also found an unexecuted Python launcher in the package, built to choose its payload by environment: a quiet, persistent foothold on systems that look corporate, and the full RAT plus credential and crypto stealers on systems that look personal. The operator appears to be limiting theft on corporate targets to avoid tripping detection.
Microsoft Threat Intelligence flagged a separate cluster of compromised websites that pre-fetch a script into the browser cache, disguised as a PNG, before the fake prompt ever appears. That hides the payload and gets around the Run dialog's character limit. Morag's advice goes after the step itself: alert on clipboard-to-Run patterns, harden PowerShell script-block logging, stop interpreters running from writable directories, and train users on the tells — fake CAPTCHAs, press-Windows+R prompts, and verification-failed screens
Source: Dark Reading