HomeYoutubeNews ClickFix attack: Fake Google Meet errors distribute malware

New ClickFix attack: Fake Google Meet errors distribute malware

A new ClickFix campaign is leading unsuspecting users to fake Google Meet conference pages that display fake connectivity errors and distribute info -stealer malware. The malware infects both Windows and macOS systems.

ClickFix is ​​a new social-engineering that emerged in May and was first reported by cybersecurity Proofpoint. It was used by a group known as TA571, which used error messages that looked like errors for Google Chrome, Microsoft Word , and OneDrive. These errors would copy a piece of PowerShell code to the clipboard, intended to fix the problem, and execute it in the Windows Command Prompt. In doing so, victims would infect their systems with various malware, including DarkGate, Matanbuchus, NetSupport, Amadey Loader, XMRig, and Lumma Stealer.

See also: Marko Polo hackers target gamers/crypto users with info-stealer malware

ClickFix Google Meet bugs distribute malware

In July, McAfee reported that ClickFix campaigns were becoming increasingly common, especially in the United States and Japan.

Now, a new report from Sekoia says that ClickFix campaigns have evolved significantly and are using fake Google Meet bugs, phishing emails targeting transportation and logistics companies, fake Facebook , and alleged GitHub issues.

According to the cybersecurity firm, some of the most recent campaigns are being conducted by two threat groups, Slavic Nation Empire (SNE) and Scamquerteo, which are considered subgroups of the Marko Polo and CryptoLove that primarily engage in crypto scams.

Fake errors in Google Meet

Attackers are using fake pages for Google Meet, which is used in many corporate environments for virtual meetings, webinars, and online collaboration.

See also: Cthulhu Stealer: New info-stealer malware targets MacOS

Hackers send victims emailsthat look like legitimate Google Meet invitations and are related to a meeting/conference or something similar.

The URLs look a lot like the actual Google Meet links:

meet[.]google[.]us-join[.]com

meet[.]google[.]web-join[.]com

meet[.]googie[.]com-join[.]us

meet[.]google[.]cdm-join[.]us

Once the victim enters the fake page, they see a message about a technical problem (e.g. microphone problem). If they click “Try Fix”, the ClickFix infection process starts, where PowerShell code copied from the website and pasted into the Windows prompt infects the computer with info-stealer malware.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Windows systems are infected with Stealc or Rhadamanthys , while macOS systems are infected with AMOS Stealer.

See also: Microsoft SmartScreen vulnerability used to distribute info-stealer malware

social engineering
New ClickFix attack: Fake Google Meet errors distribute malware

In an earlier report on ClickFix social engineering campaigns, McAfee suggested the following protection measures:

  • Educating users about social engineering tactics and phishing attacks
  • Install (and update) antivirus and anti-malware software on all endpoints
  • Implement powerful email filters to block phishing emails and malicious attachments
  • Use of firewalls and intrusion detection/prevention systems (IDS/IPS)
  • Network segmentation to limit the spread of malware
  • Implementation of the principle of least privilege (PoLP), so that users only have access to necessary resources
  • Multi-factor authentication (MFA) implementation
  • Updating operating systems, software and applications
  • Encryption of sensitive data
  • Continuous monitoring and analysis of system and network logs

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS