AUTO-UPDATED

ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures

Cybersecurity researchers have identified multiple active campaigns using ClickFix social engineering to deploy sophisticated malware loaders, including BabaDeda, Lorem Ipsum, and Potemkin, across various global industry sectors.

Key Points

  • ClickFix attacks deceive users into executing malicious PowerShell commands by masquerading as legitimate browser security updates or troubleshooting instructions.
  • The BabaDeda Loader, linked to the Vanilla Tempest threat group, uses stealthy techniques like DLL side-loading and in-memory shellcode to drop information stealers and ransomware.
  • Lorem Ipsum Loader is distributed via compromised WordPress sites and utilizes outdated Node.js versions to execute JavaScript-based payloads and establish persistent backdoors.
  • The Potemkin loader employs a domain generation algorithm (DGA) to communicate with command-and-control servers and facilitates the deployment of RMMProject and EtherRAT.
  • These modular frameworks allow attackers to separate delivery, storage, and execution, significantly complicating forensic analysis and detection by traditional security tools.

Why it Matters

These campaigns demonstrate how threat actors rapidly pivot their delivery infrastructure to bypass security measures like code-signing requirements. By exploiting human behavior through simple, authoritative-looking instructions, attackers continue to successfully compromise systems and deploy high-impact threats like ransomware.
Internet Published by info@thehackernews.com (The Hacker News)
Read original