More than 100 car dealership websites were found to be running malicious ClickFix code , after a third-party domain was compromised in a supply chain attack.
See also: US: They don't know who is behind the cyberattack on X

As part of the deal, an attacker infected LES Automotive, a shared video service exclusively available to stores, causing websites using the service to display a ClickFix page to their visitors.
A ClickFix attack is based on malicious code on a web page that displays a message to the user, asking them to fix an error or complete a reCAPTCHAin order to prove they are human.
When the user clicks on the prompt, a malicious command is copied to the clipboard, while also instructing them to execute key combinations that open the Windows Run prompt, paste the copied command into the prompt, and execute it.
The social engineering has been used for several years, but began to gain popularity among cybercriminals and APTs last year, with an increase in its adoption seen in recent months.
See also: Switzerland: Critical infrastructures must report cyberattacks
In October 2024, HHS warned of Russian-speaking cybercriminals using the ClickFix technique in their attacks since at least April 2024.

ClickFix has been used to spread infostealer and other types of malware to users across various sectors. Recently, Microsoft warned of an extensive campaign targeting the hosting industry.
Security researcher Randy McEoin warned that visitors to the websites of more than 100 car dealerships using LES Automotive were targeted by a ClickFix attack that distributed the SectopRAT.
The attack used ClickFix's fake reCAPTCHA variant, relying on PowerShell commands to deploy payloads on the victim's machine, with the ultimate goal of infecting them with the remote access virus.
The JavaScript code designed to copy the malicious code to the clipboard, McEoin discovered, included at least one comment in Russian. He notes that users often received a harmless version of the script, suggesting that the insertion was likely done dynamically.
See also: Lee Enterprises: Recent cyberattack was ransomware
A supply chain attack is when someone attacks an organization through another organization or company that the former collaborates with or depends on. Instead of attacking the target organization directly, the attacker tries to enter through a weak link in the supply chain, such as suppliers, partners, or even software that the organization uses.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: securityweek
