New ClickFix Scam Tricks Users Into Mapping Hacker-Controlled Drives
ID: cdf301bf-4dbc-56c8-b6b7-7e3204af5ec8
STIX ID: report--cdf301bf-4dbc-56c8-b6b7-7e3204af5ec8
Feed Name: HackRead
Threat Score
A ClickFix phishing campaign uses a clipboard trick (prompting users to run Win+R and paste a hidden command) to execute 'net use', map a remote drive, and download a legitimate-signed app (WorkFlowy) whose asar archive has been swapped with malicious Node.js code; the payload runs in-process with user privileges, avoids writing files to disk, generates a victim ID, and beacons to attacker-controlled servers, leaving only RunMRU registry entries as reliable forensic traces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
