New FileFix attack uses cache smuggling to evade security software
ID: fe13e6dd-72d1-513a-a068-6f95aa34beb1
STIX ID: report--fe13e6dd-72d1-513a-a068-6f95aa34beb1
Feed Name: Bleeping Computer
The report describes a FileFix variant that tricks victims into pasting a padded clipboard path into the Windows File Explorer address bar; the padding hides a headless PowerShell command that copies a cached fake-image from Chrome’s cache, extracts an embedded ZIP and executes a malicious executable. This cache-smuggling technique avoids explicit web downloads and can evade many security products; researchers also observed a ClickFix generator kit used to create these lures and noted adoption by ransomware and infostealer operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
