logo

FileFix Attack Chain Enables Malicious Script Execution

ID: 00b2d920-da93-59d4-8270-1caa05031ca4

STIX ID: report--00b2d920-da93-59d4-8270-1caa05031ca4

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2025-07-02

Date Updated: 2026-04-21

Author: Kristina Beek

...
...

A researcher disclosed a FileFix/ClickFix attack chain that uses social engineering to get victims to save malicious webpages as .HTA or paste PowerShell commands, bypassing Windows Mark of the Web protections and auto-executing scripts via mshta.exe; the technique has been observed in widespread website compromises (thousands of WordPress sites and over 100 car dealership sites) and can be mitigated by disabling mshta.exe, showing file extensions, and blocking HTML attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.