Two recently uncovered campaigns use ClickFix-style attacks to steal credentials and cryptocurrency as well as to go deeper into the enterprise network to maintain long-term persistence in compromised systems. The attacks, while separate, demonstrate how threat actors continue to evolve the social engineering tactic to exploit commonly used services and engage in more complex malicious activities.
Researchers from Cisco Talos discovered both campaigns, which use different delivery methods, but both rely on the victim to take a seemingly routine action to compromise themselves, according to two separate reports by the networking firm's threat research lab published today. The link between the two was not only in their use of social engineering attacks, commonly known as ClickFix and ClearFake, but also in how they abused legitimate services and assets to make the malicious activity resemble typical user or application behavior, according to the researchers.
Related:ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
"Both operations turn the victim into an active part of the infection chain and abuse services or technologies that users and defenders normally regard as legitimate," Vanja Svajcer, senior threat researcher at Cisco Talos, tells Dark Reading. "They also show attackers moving into places where conventional network detection has less context, like browser sessions, trusted cloud services, public blockchain infrastructure, and signed or legitimate software components."
New Attacks Demonstrate ClickFix Diversity
In one attack, aimed at stealing cryptocurrency, threat actors used a ClickFix-style approach to coerce users into pasting malicious code that can alter transaction interface pages in Chrome or add it through a browser extension. In a deviation from typical ClickFix attacks, the attackers convince potential victims to retrieve and enter malicious browser code from a publicly available Google Sheet, using a legitimate Google service as part of their infrastructure.
The other attack on a Ukrainian government organization by a Russian threat actor used what is known as a ClearFake and shows victims a phony Google CAPTCHA, instructing them to run a malicious command. That command executes various malware that can steal cryptocurrency and credentials, deploy a reverse proxy, and install an unauthorized remote access tool.
Together, the attacks demonstrate the evolution of these related social engineering approaches and how a single deceptive prompt can open the door to financial theft, credential theft, and deeper compromise, the researchers said.
Related:'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
Abusing Legitimate Google Services
... continue reading