ClickFix campaigns are once again turning an ordinary user action into the opening move of a serious intrusion. A newly documented chain uses a fake fix prompt to lead victims toward CNCMachineRMS, a previously undocumented remote access trojan that gives an attacker lasting control of a Windows device. The campaign stands out because it hides behind software that is both legitimate and signed. After the ClickFix lure, attackers launch IBM SPSS WinWrap Basic IDE and steer its scripting function toward malicious files, allowing the activity to blend in with trusted software rather than an obviously hostile program. LevelBlue said in a report shared with Cyber Security News (CSN) that the chain also uses four decoy DLLs and a...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!