New ClickFix attack deploys Havoc C2 via Microsoft Sharepoint
ID: 79ef0d66-e5e1-565c-b127-ab95ce427db6
STIX ID: report--79ef0d66-e5e1-565c-b127-ab95ce427db6
Feed Name: Bleeping Computer
A ClickFix phishing campaign distributes an HTML attachment that displays a fake OneDrive error and persuades victims to paste a copied PowerShell command; the command retrieves a script from a threat-controlled SharePoint site that installs Python (if absent) and deploys the Havok post‑exploitation framework as an injected DLL. Havok is then used for remote access and is configured to use Microsoft Graph/SharePoint APIs for C2, allowing attackers to hide communications within legitimate cloud traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
