New ClickFix ‘Word Online’ Message Tricks Users into Installing DarkGate Malware
ID: ca3b1b5c-83d9-582c-9917-b5512bb9e491
STIX ID: report--ca3b1b5c-83d9-582c-9917-b5512bb9e491
Feed Name: cybersecurityNews.com
Threat Score
This report describes the "ClickFix" social-engineering campaign that mimics a missing browser extension error to persuade users to open PowerShell and paste a malicious "fix" command copied by the webpage; the command fetches a dark.hta file which drops an AutoIt executable and an encrypted payload decrypted with DES to install the DarkGate remote access trojan, enabling full system compromise and C2 communication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
