ClickFix tactic: The Phantom Meet Infostealer Campaign
ID: 08e55fd4-ff61-5343-a6af-136e1d093726
STIX ID: report--08e55fd4-ff61-5343-a6af-136e1d093726
Feed Name: Sekoia.com
This report describes the emergence and use of the "ClickFix" social-engineering tactic (2024) where fake browser error dialogs on impersonated pages (notably Google Meet) prompt victims to copy/execute PowerShell/HTA/VBS payloads, enabling distribution of infostealers and RATs (Stealc, Rhadamanthys, AMOS Stealer). It provides a chronological campaign overview, technical analysis of the Google Meet cluster (payloads, C2s, domains, hashes), IoCs, victimology, and attribution to traffer teams Slavic Nation Empire (SNE) and Scamquerteo operating within cryptocurrency scam ecosystems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
