logo

Cut & Paste Tactics Import Malware to Unwitting Victims

ID: 4909838f-e55e-5bb4-ac18-13dda7bbbeea

STIX ID: report--4909838f-e55e-5bb4-ac18-13dda7bbbeea

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-06-18

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Proofpoint observed active campaigns (ClearFake and ClickFix) and TA571 using socially engineered fake browser updates and error pop-ups that instruct victims to copy-and-paste PowerShell scripts, resulting in installation of multiple malware families (DarkGate, NetSupport, Matanbuchus, Amadey, Lumma, Vidar). The campaigns employ compromised websites, blockchain-hosted scripts (EtherHiding), and iframe injections, impacted thousands of organizations with over 100,000 messages observed; Proofpoint published IoCs and recommends user training and reporting to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.