New ClickFix attacks abuse Windows App-V scripts to push malware
ID: d54c549d-ed64-5847-b46b-78f8fb30c176
STIX ID: report--d54c549d-ed64-5847-b46b-78f8fb30c176
Feed Name: Bleeping Computer
A ClickFix social-engineering campaign is delivering the Amatera infostealer by tricking victims into pasting a command that abuses the signed SyncAppvPublishingServer.vbs (App‑V) to launch PowerShell, perform anti-analysis checks, fetch base64 configuration from a public Google Calendar event, retrieve encrypted payloads hidden via LSB steganography in PNGs hosted on CDNs, and execute shellcode in memory; the report highlights the chain's use of living‑off‑the‑land binaries, WMI, and WinINet API calls and recommends restricting Run dialog access, removing unneeded App‑V components, and enabling PowerShell logging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
