New FileFix Method Emerges as a Threat Following 517% Rise in ClickFix Attacks

ESET research shows that between the second half of 2024 and the first half of this year, the ClickFix social engineering technique as an initial access vector employing phoney CAPTCHA verifications grew by 517%.

The list of dangers that ClickFix attacks cause is constantly expanding and now includes ransomware, cryptominers, infostealers, remote access trojans, post-exploitation tools, and even custom malware from threat actors with ties to nation-states. ESET’s Threat Prevention Labs Director Jiří Kropáč stated.

ClickFix is a well-known and dishonest technique that uses fake error messages or CAPTCHA verification checks to trick users into copying and pasting a malicious script into the Apple macOS Terminal software or the Windows Run dialogue box, then running it.

According to the Slovak cybersecurity firm, Japan, Peru, Poland, Spain, and Slovakia account for the majority of ClickFix detections.

Due to the popularity and efficacy of this attack technique, threat actors are now promoting builders that give ClickFix-weaponized landing pages to other attackers read more about New FileFix Method Emerges as a Threat Following 517% Rise in ClickFix Attacks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *