Cybersecurity researchers have identified multiple active campaigns using ClickFix social engineering to deploy sophisticated malware loaders, including BabaDeda, Lorem Ipsum, and Potemkin, across various global industry sectors.
Key Points
- ClickFix attacks deceive users into executing malicious PowerShell commands by masquerading as legitimate browser security updates or troubleshooting instructions.
- The BabaDeda Loader, linked to the Vanilla Tempest threat group, uses stealthy techniques like DLL side-loading and in-memory shellcode to drop information stealers and ransomware.
- Lorem Ipsum Loader is distributed via compromised WordPress sites and utilizes outdated Node.js versions to execute JavaScript-based payloads and establish persistent backdoors.
- The Potemkin loader employs a domain generation algorithm (DGA) to communicate with command-and-control servers and facilitates the deployment of RMMProject and EtherRAT.
- These modular frameworks allow attackers to separate delivery, storage, and execution, significantly complicating forensic analysis and detection by traditional security tools.