logo

ClickFix Attacks Still Using the Finger, (Sat, Dec 13th)

ID: 9122db52-c695-5f2a-9298-b94626819900

STIX ID: report--9122db52-c695-5f2a-9298-b94626819900

Feed Name: SANS ISC Diary

Threat Score
55/100

Date Published: 2025-12-13

Date Updated: 2026-04-19

...
...

This report documents active ClickFix social-engineering campaigns (observed Nov–Dec 2025) that misuse the legacy finger protocol (TCP/79) via Windows finger.exe to fetch and execute malicious content — including Base64-encoded PowerShell and files from domains such as pmidpils.com/yhb.jpg. Network captures from KongTuke and SmartApeSG show finger commands returned script content that downloads and runs payloads; environments that block TCP/79 (explicit proxy) can mitigate this technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.