Phishing Frenzy: Cyber Tricksters Use ClickFix to Unleash Havoc on Unsuspecting Users

Phishing campaigns now use the cunning ClickFix technique to hide malware behind SharePoint sites. The ploy tricks users into executing a malicious PowerShell command, with the Havoc Demon agent lurking in the shadows. Remember, if a SharePoint site looks too friendly, it might just be phishing for trouble!

Pro Dashboard

Hot Take:

In the world of cyber shenanigans, it seems like the bad guys never take a coffee break! This time, they’re using SharePoint and the Microsoft Graph API to turn an innocent-sounding “Documents.html” into a high-stakes game of “Guess what malware’s in the box!” It’s like a cybersecurity version of those Russian nesting dolls, except this one could mess up your day. Let’s dive in before they hack the WiFi at your local coffee shop!

Key Points:

  • Cybercriminals are using the ClickFix technique to deliver a C2 framework called Havoc.
  • The attack starts with a phishing email containing an HTML attachment that tricks users into executing malicious commands.
  • Malware stages are hidden behind a SharePoint site, utilizing the Microsoft Graph API to obscure communications.
  • The framework supports operations such as information gathering, file operations, and Kerberos attacks.
  • Malwarebytes highlights ongoing exploitation of Google Ads policies to target PayPal users with fake ads.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?