logo

Fake Google Chrome errors trick you into running malicious PowerShell scripts

ID: 22ef0a29-ad6c-5cd5-97e0-78960085f9a0

STIX ID: report--22ef0a29-ad6c-5cd5-97e0-78960085f9a0

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-06-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Proofpoint observed multiple active campaigns (ClearFake, a ClickFix cluster, and TA571) using fake Google Chrome, Microsoft Word, and OneDrive overlays that instruct victims to copy-and-paste PowerShell "fix" commands from the clipboard. Executing the provided commands results in additional scripts being fetched and deployed—leading to infections by DarkGate, Matanbuchus, NetSupport, Amadey Loader, XMRig, a clipboard hijacker, and Lumma Stealer—while attackers exploit social engineering and browser/Windows behaviors to bypass detection and scale delivery (including via spam and compromised sites).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.