logo

Decades-old ‘Finger’ protocol abused in ClickFix malware attacks

ID: 073bf0e4-2bb7-51ec-bade-a96cf9987030

STIX ID: report--073bf0e4-2bb7-51ec-bade-a96cf9987030

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-11-15

Date Updated: 2026-07-17

Author: Lawrence Abrams

...
...

Researchers observed active ClickFix campaigns abusing the Finger protocol (TCP/79) and the Windows finger command as a LOLBIN to fetch and pipe remote commands into cmd.exe; actors used social engineering to trick victims into executing these commands, which download and install payloads (a Python infostealer and NetSupport Manager RAT), perform anti-analysis checks, and establish persistence via scheduled tasks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.