<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

New FileFix Phishing Attack Spreads Globally, Tricking Users Through File Explorer

Beware of the new "FileFix" phishing scam impersonating Facebook security, tricking users into executing malware via File Explorer.
Content Team

A sophisticated new phishing campaign using the "FileFix" technique has spread across 16 countries, from the US to Serbia. The attack impersonates Facebook security warnings, claiming accounts will be suspended unless users take action.

When victims click to "appeal," they're tricked into pasting malicious PowerShell code into Windows File Explorer's address bar under the guise of opening a PDF file. This executes hidden malware that downloads AI-generated images containing steganographically hidden code, ultimately deploying StealC infostealer to harvest passwords and sensitive data.

FileFix builds on the earlier "ClickFix" technique but uses the more familiar File Explorer instead of the Run dialog, making it harder for organizations to block and more likely to fool users unfamiliar with command execution.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo