Cut & Paste Tactics Import Malware to Unwitting Victims
ID: 4909838f-e55e-5bb4-ac18-13dda7bbbeea
STIX ID: report--4909838f-e55e-5bb4-ac18-13dda7bbbeea
Feed Name: Dark Reading
Date Published: 2024-06-18
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Proofpoint observed active campaigns (ClearFake and ClickFix) and TA571 using socially engineered fake browser updates and error pop-ups that instruct victims to copy-and-paste PowerShell scripts, resulting in installation of multiple malware families (DarkGate, NetSupport, Matanbuchus, Amadey, Lumma, Vidar). The campaigns employ compromised websites, blockchain-hosted scripts (EtherHiding), and iframe injections, impacted thousands of organizations with over 100,000 messages observed; Proofpoint published IoCs and recommends user training and reporting to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
