Skip to content
Tech News
← Back to articles

ClickFix Campaigns Abuse Legitimate Services for Persistent Access

read original get YubiKey 5 NFC Security Key → more articles
Why This Matters

Cisco Talos has documented two new ClickFix/ClearFake campaigns that trick users into pasting malicious code themselves, then hide behind trusted infrastructure like Google Sheets, cloud services, blockchain, and signed software. Because the activity blends into normal browser and cloud behavior, conventional network detection has little context to catch it, raising the bar for enterprise defenders and everyday crypto users alike.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — Campaigns like ClickFix thrive on tricking people into handing over credentials, and a hardware security key makes stolen passwords far less useful. The YubiKey 5 NFC plugs into USB-A or taps to a phone via NFC for phishing-resistant logins across major accounts and password managers.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Two recently uncovered campaigns use ClickFix-style attacks to steal credentials and cryptocurrency as well as to go deeper into the enterprise network to maintain long-term persistence in compromised systems. The attacks, while separate, demonstrate how threat actors continue to evolve the social engineering tactic to exploit commonly used services and engage in more complex malicious activities.

Researchers from Cisco Talos discovered both campaigns, which use different delivery methods, but both rely on the victim to take a seemingly routine action to compromise themselves, according to two separate reports by the networking firm's threat research lab published today. The link between the two was not only in their use of social engineering attacks, commonly known as ClickFix and ClearFake, but also in how they abused legitimate services and assets to make the malicious activity resemble typical user or application behavior, according to the researchers.

Related:ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

"Both operations turn the victim into an active part of the infection chain and abuse services or technologies that users and defenders normally regard as legitimate," Vanja Svajcer, senior threat researcher at Cisco Talos, tells Dark Reading. "They also show attackers moving into places where conventional network detection has less context, like browser sessions, trusted cloud services, public blockchain infrastructure, and signed or legitimate software components."

New Attacks Demonstrate ClickFix Diversity

In one attack, aimed at stealing cryptocurrency, threat actors used a ClickFix-style approach to coerce users into pasting malicious code that can alter transaction interface pages in Chrome or add it through a browser extension. In a deviation from typical ClickFix attacks, the attackers convince potential victims to retrieve and enter malicious browser code from a publicly available Google Sheet, using a legitimate Google service as part of their infrastructure.

The other attack on a Ukrainian government organization by a Russian threat actor used what is known as a ClearFake and shows victims a phony Google CAPTCHA, instructing them to run a malicious command. That command executes various malware that can steal cryptocurrency and credentials, deploy a reverse proxy, and install an unauthorized remote access tool.

Together, the attacks demonstrate the evolution of these related social engineering approaches and how a single deceptive prompt can open the door to financial theft, credential theft, and deeper compromise, the researchers said.

Related:'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

Abusing Legitimate Google Services

... continue reading