HomeSecurityClickFix: Fake Windows update to distribute malware

ClickFix: Fake Windows update to distribute malware

Cybercriminals are constantly evolving their social engineering, with ClickFix being one of the most dangerous and effective forms of attack. It is a methodology that relies on tricking the user into copying and executing malicious code from within the Windows environment — a process that is often disguised as a necessary update or system check.

ClickFix Windows malware update

Realistic Windows Update pages and full-screen tricks

In recent weeks, security researchers have identified new variations of the attack, where attackers display a fake, highly realistic Windows Update animation in full screen. The page appears to “lock” the system, forcing victims to follow specific instructions to supposedly “complete” a critical update.

See also: CISA: Spyware campaigns target Signal & WhatsApp users

Other versions use “human verification”to verify that the user is not a bot. In reality, every command the user types triggers malicious code that has already been automatically copied to the clipboard via JavaScript.

What is ClickFix really?

ClickFix is ​​a social engineering attack that aims to deceive. Instead of trying to exploit a vulnerability in the software, the attacker tries to convince the user to activate the attack. By simply pasting commands into PowerShell or the Windows command line, the system is immediately infected with malware — in this case, the infostealers LummaC2 and Rhadamanthys.

The simplicity and effectiveness of this method have led to the rapid spread of the technique at all levels of cybercrime.

ClickFix: Fake Windows update to distribute malware

Steganography: Code hidden within images

One of the most striking aspects of the new variant is the use of steganography. The final malicious code is hidden within the pixels of PNG files.

See also: New version of Shai-Hulud worm spreads via npm, GitHub

According to Huntress, the decompression and execution of the payload occurs in multiple stages:

  • Using mshta.exe to launch the malicious process.
  • Execute PowerShell code that loads Stego Loader.
  • Stego Loader reconstructs the encrypted code from within the PNG, using custom C#.
  • The final shellcode is run through the Donut, directly in memory, bypassing detection mechanisms.

The complexity and fragmentation of the attack make detection even more difficult.

Avoidance tactics and dynamic deception techniques

Another method observed is the use of “ctrampoline” — a technique where the initial execution point calls thousands of empty functions in order to confuse analyzers and detection tools. The end result is the silent loading of powerful info-stealers.

Recently, following Operation Endgame, part of the Rhadamanthys infrastructure was taken down. However, the Windows Update decoys remain active, although they no longer download the final payload.

See also: Hackers replace the letter 'm' with the combination 'rn' in Microsoft

ClickFix: Fake Windows update to distribute malware

How users and organizations can protect themselves

Experts give clear instructions for avoiding such attacks:

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

  • Disable the Windows Run box where possible
  • Monitor suspicious processes, e.g. explorer.exe spawning mshta.exe or PowerShell.
  • Check the RunMRU key in the registry for command history.
  • Educate users not to execute commands originating from websites.

The ClickFix attacks demonstrate that cybercriminals continue to invest in techniques that rely on user psychology rather than technology alone. Vigilance and awareness are the most important defense tools.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS