'JackFix' Attack Circumvents ClickFix Mitigations
ID: bf6ec123-ad4c-582f-87fd-4c5111953ea4
STIX ID: report--bf6ec123-ad4c-582f-87fd-4c5111953ea4
Feed Name: Dark Reading
JackFix is a ClickFix-derived phishing campaign that lures users to fake sites, displays a convincing full-screen fake Windows crash/lock to panic victims, and coerces them into executing commands that fetch an obfuscated PowerShell loader; that loader disables Defender protections and deploys multiple commercial infostealers (Rhadamanthys, Vidar 2.0, RedLine, Amadey). The campaign includes evasive techniques such as runtime reconstruction of payloads and content-based URL gating to avoid analysis and detection, and has generated hundreds of VirusTotal reports across the US and Europe; mitigation advice includes disabling Windows Run for users and limiting browser full-screen capability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
