New FileFix attack weaponizes Windows File Explorer for stealthy commands
ID: 89969086-c0c4-59ab-8b0f-7bbf838a8d72
STIX ID: report--89969086-c0c4-59ab-8b0f-7bbf838a8d72
Feed Name: Bleeping Computer
Threat Score
FileFix is a newly demonstrated variant of the ClickFix social-engineering attack that tricks users into executing malicious PowerShell commands by using the Windows File Explorer address bar and the browser file-upload feature; the technique hides the payload in a commented dummy file path so the malicious command is not visible, and the researcher warns it could be quickly adopted by attackers given prior ClickFix use in ransomware and infostealer campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
