New Clickfix Exploit Tricks Users into Changing DNS Settings for Malware Installation
ID: 9ce798ee-956c-5244-b307-e073e385608e
STIX ID: report--9ce798ee-956c-5244-b307-e073e385608e
Feed Name: cybersecurityNews.com
The ClickFix campaign lures victims with fake error prompts to paste and execute a script that performs attacker-controlled DNS lookups; the DNS response contains the second-stage payload encoded in the Name field, which is executed to download a portable Python bundle and run reconnaissance and persistence routines, culminating in the deployment of ModeloRAT. The technique uses DNS as a lightweight staging and C2 channel to evade detection and validate targets before delivering heavier malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
