ClickFix Attacks Still Using the Finger, (Sat, Dec 13th)
ID: 9122db52-c695-5f2a-9298-b94626819900
STIX ID: report--9122db52-c695-5f2a-9298-b94626819900
Feed Name: SANS ISC Diary
This report documents active ClickFix social-engineering campaigns (observed Nov–Dec 2025) that misuse the legacy finger protocol (TCP/79) via Windows finger.exe to fetch and execute malicious content — including Base64-encoded PowerShell and files from domains such as pmidpils.com/yhb.jpg. Network captures from KongTuke and SmartApeSG show finger commands returned script content that downloads and runs payloads; environments that block TCP/79 (explicit proxy) can mitigate this technique.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
