HomeSecurityExpansion of ClickFix attacks using fake CAPTCHAs

Expansion of ClickFix attacks using fake CAPTCHAs

Cybersecurity researchers have revealed details of a new campaign that combines fake ClickFix-style CAPTCHAs with a signed Microsoft Application Virtualization (App-V) to distribute an infostealer called Amatera.

See also: New ErrTraffic service allows ClickFix attacks

ClickFix

“ Instead of executing PowerShell directly, the attacker uses this script to control how execution begins and avoid more common, easily identifiable execution paths ,” Blackpoint researchers Jack Patrick and Sam Decker said in a report published last week.

The idea is to turn the App-V script into a “living-off-the-land” (LotL) binary that acts as an intermediary to execute PowerShell through a trusted Microsoft component to hide malicious activity.

The starting point of the attack is a fake CAPTCHA verification prompt that attempts to trick users into pasting and executing a malicious command into the Run . However, the provided command, instead of calling PowerShell directly, exploits “SyncAppvPublishingServer.vbs,” a signed Visual Basic script associated with App-V to retrieve and execute a loader in memory from an external server using “wscript.exe.”

The misuse of “SyncAppvPublishingServer.vbs” is not new. In 2022, two different threat actors from China and North Korea, known as DarkHotel and BlueNoroff, were observed using the LOLBin exploit to secretly execute a PowerShell script. But this is the first time it has been observed in ClickFix attacks.

See also: BlackForce: New phishing kit steals credentials through MitB attacks

Expansion of ClickFix attacks using fake CAPTCHAs
Expansion of ClickFix attacks using fake CAPTCHAs

“Hackers can exploit SyncAppvPublishingServer.vbs to bypass PowerShell execution restrictions and evade defensive measures by ‘living off the land,’” notes MITRE in the ATT&CK framework. “Execution through the middle can act as a trusted/signed alternative to directly invoking ‘powershell.exe.’“

Using an App-V script is important because the virtualization solution is only built into Enterprise and Education of Windows 10 and Windows 11, along with modern Windows Server editions. It is not available for Windows Home or Pro installations.

On Windows operating systems where App-V is either absent or not enabled, the command fails completely, suggesting that enterprise-managed systems are likely the primary targets of the campaign.

The disguised loader performs checks to ensure it is not running in sandbox environments and then proceeds to retrieve configuration data from a public Google Calendar (ICS) file, essentially turning a trusted third-party service into a “dead drop” resolver

Analysis of the log event file leads to the recovery of additional loader stages, including a PowerShell script that acts as an intermediate loader to execute the next stage, another PowerShell script, directly in memory. This step leads to the recovery of a PNG image from domains such as “gcdnb.pbrd[.]co” and “iili[.]io” via WinINet APIs that hides an encrypted and compressed PowerShell payload.

See also: ConsentFix: A new variant of the ClickFix phishing attack

Expansion of ClickFix attacks using fake CAPTCHAs

The resulting script is decrypted, GZip-decompressed in memory, and executed using Invoke-Expression, ultimately resulting in the execution of a shellcode loader designed to launch the Amatera Stealer.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS