logo

ClickFix Attack Compromises 100+ Car Dealership Sites

ID: e45f7538-e64c-5179-a067-d7791111072a

STIX ID: report--e45f7538-e64c-5179-a067-d7791111072a

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-03-17

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

A supply-chain compromise of LES Automotive caused more than 100 car dealership websites to serve malicious "ClickFix" code that tricks visitors into pasting a copied command into the Windows Run prompt, enabling deployment of SectopRAT. The brief connects this incident to prior ClickFix/fake-update campaigns and an actor tracked as Storm-1865 that has used similar tactics (including phishing and clipboard/command-execution techniques) across hospitality and other industries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.