New ClickFix attack Hides in Native Windows Tools to Reduce Detection Risk
ID: 6400d7d3-56bc-5c3e-bc79-020675c9b747
STIX ID: report--6400d7d3-56bc-5c3e-bc79-020675c9b747
Feed Name: HackRead
Threat Score
CyberProof identified a ClickFix campaign where attackers socially engineer Windows users with fake CAPTCHA prompts to paste a Win+R command that uses LOLBins (cmdkey, regsvr32) to fetch a remote DLL (demo.dll) from 151.245.195.142, execute it via DllRegisterServer/CreateProcessA, and persist via a scheduled task named RunNotepadNow with remote task instructions in 777.xml; the campaign emphasizes stealth by avoiding PowerShell and using trusted Windows components.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
