A recently uncovered phishing attack, ClickFix, tricks victims into executing malicious PowerShell that deploy Havoc C2 to remotely access compromised devices.
See also: ClickFix exploits users with fake errors

ClickFix is a social engineering that emerged last year, where threat actors create phishing websites or email attachments that display fake errors and then ask the user to click a button to fix them.
Clicking the button will copy a malicious PowerShell command to the Windows clipboard, which users are prompted to paste into a command prompt to “fix” the error. However, as expected, the malicious PowerShell command will execute a script hosted on a remote website that downloads and installs malware on devices.
In a new ClickFix attack discovered by Fortiguard , hackers send phishing emails, stating that a "restricted access notice" is available for review and that recipients must open the attached HTML document ('Documents.html') to view it.
When opened, the HTML displays a fake error 0x8004de86 , stating that “ Connection to the cloud service “One Drive” failed ” and that users need to fix the error by manually updating the DNS cache
See also: Hackers exploit ClickFix to deploy NetSupport RAT
Clicking the “How to Fix It” button will automatically copy a PowerShell command to the Windows clipboard and then display instructions on how to run it. This PowerShell command will attempt to launch another PowerShell script hosted on the hacker’s SharePoint server.

Fortiguard says the script checks whether the device is in a sandbox environment by querying the number of devices in the Windows domain. If it determines that it is in a sandbox, the script will terminate. Otherwise, the script will modify the Windows registry to add a value indicating that the script was executed on the device. It will then proceed to check whether Python is installed on the device, and if not, it will install the interpreter.
Finally, a Python script is downloaded from the same SharePoint site and executed to deploy the command and control framework after exploiting Havok as a DLL.
ClickFix attacks have become increasingly popular among cybercriminals, who use them to deploy a wide variety of malware, including infostealers , DarkGate, and remote access trojans
See also: Alarming rise in ClickFix attacks via Malvertising “DeceptionAds”
A phishing campaign is a deceptive attempt, usually over the internet, to extract personal or sensitive information from the target, such as passwords, credit card numbers, or other personal information. Typically, attackers use fake websites, emails, or SMS messages that appear to come from trusted sources (such as banks, services, or well-known companies) in order to trick the victim into revealing this sensitive information.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
