ClickFix Attack Compromises 100+ Car Dealership Sites
ID: e45f7538-e64c-5179-a067-d7791111072a
STIX ID: report--e45f7538-e64c-5179-a067-d7791111072a
Feed Name: Dark Reading
Date Published: 2025-03-17
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
A supply-chain compromise of LES Automotive caused more than 100 car dealership websites to serve malicious "ClickFix" code that tricks visitors into pasting a copied command into the Windows Run prompt, enabling deployment of SectopRAT. The brief connects this incident to prior ClickFix/fake-update campaigns and an actor tracked as Storm-1865 that has used similar tactics (including phishing and clipboard/command-execution techniques) across hospitality and other industries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
