HomeSecurityClickfix attack promises “Free WiFi” but distributes malware

Clickfix attack promises “Free WiFi” but distributes malware

Researchers have uncovered a sophisticated social engineering campaign, dubbed “Clickfix,” that exploits the public’s need for free internet access by using deceptive Wi-Fi portals. The attackers’ goal is to trick users into downloading and executing PowerShell-based malware.

Clickfix “Free WiFi” malware attack

The Clickfix attack uses the user's own actions in the browser to compromise their system under the guise of a simple verification step.

The attack targets people in public places, such as airports, where the promise of “Free Wi-Fi” is a powerful lure. Unsuspecting users attempting to connect are redirected to a professionally designed but fake captive portal. These pages, often hosted on insecure IP addresses (instead of legitimate domains), mimic real network connection screens, complete with logos and a CAPTCHA prompt to “prove the user is not a robot.” This is a feature designed to create a false sense of security.

See also: Wi-Fi pitfalls: A cybersecurity guide for vacations

Clickfix Attack: Exploiting User Behavior

The essence of the Clickfix attack lies in the clever manipulation of user behavior. After the user interacts with the fake CAPTCHA, a pop-up window appears with a series of “Verification Steps”. Instead of a simple click, the instructions guide the user through a specific sequence of keyboard shortcuts: press Ctrl+S to save the page, go to the browser’s downloads window, and press Enter to open the file. This sequence is a social engineering trick designed to bypass standard browser security warnings about downloading executable files.

Clickfix attack promises “Free WiFi” but distributes malware

By instructing the user to save the page and run the file themselves, the attackers are essentially gaining consent to execute malicious code. The file that is downloaded is not an image or document, but a script that initiates the infection. Once the user unwittingly executes the downloaded file, a malicious PowerShell script.

Analysis of the attack chain with ANY.RUN Sandbox reveals that this script acts as a downloader, establishing a connection to a command and control server to download the main malicious payload. In this campaign, the payload has been identified as a network trojan.

See also: How to tell if your Wi-Fi router has been hacked?

PowerShell is a powerful tool for attackers because it is built into Windows and can execute commands, scripts, and payloads directly in memory, often avoiding detection by traditional antivirus solutions. This type of fileless malware can be used for a wide range of malicious activities, including stealing sensitive information, deploying ransomware, or providing a backdoor for remote access to the compromised device.

Clickfix attack promises “Free WiFi” but distributes malware

Protection

To protect yourself from the dangers of public networks , it's essential to take precautions when using them. The most effective way to stay safe is to avoid connecting to public Wi-Fi altogether.

If you must use a public network, make sure it is legitimate by verifying its name and location, or use a VPN (Virtual Private Network) service. Using a VPN can encrypt your internet and provide an extra layer of protection from hackers on unsecured networks. It also allows you to bypass any restrictions set by the network administrator.

See also: How to improve the performance of your home Wi-Fi?

Additionally, avoid accessing sensitive websites, such as banks or websites that require personal information, and make sure that the websites you visit use the HTTPS instead of HTTP. HTTPS encrypts the communication between your browser and the website, offering an extra layer of protection.

a good practice to disable automatic connection to networks WiFi This will prevent you from accidentally connecting to unsecured networks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Finally, update your device's software regularly. Software updates often include security that can help protect your data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS