logo

New ClickFix attack deploys Havoc C2 via Microsoft Sharepoint

ID: 79ef0d66-e5e1-565c-b127-ab95ce427db6

STIX ID: report--79ef0d66-e5e1-565c-b127-ab95ce427db6

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-03-03

Date Updated: 2026-03-27

Author: Lawrence Abrams

...
...

A ClickFix phishing campaign distributes an HTML attachment that displays a fake OneDrive error and persuades victims to paste a copied PowerShell command; the command retrieves a script from a threat-controlled SharePoint site that installs Python (if absent) and deploys the Havok post‑exploitation framework as an injected DLL. Havok is then used for remote access and is configured to use Microsoft Graph/SharePoint APIs for C2, allowing attackers to hide communications within legitimate cloud traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.