‘Fix It’ social-engineering scheme impersonates several brands
ID: 7b584fe8-4a5a-50e2-b68f-6e4522715f2e
STIX ID: report--7b584fe8-4a5a-50e2-b68f-6e4522715f2e
Feed Name: Malwarebytes Blog
Malicious ads and lookalike software/download pages are luring victims to a fake Cloudflare verification that copies a PowerShell command to the clipboard; victims are instructed to open Run and paste/execute the command, which downloads a payload from topsportracing.com and sends system fingerprinting data to a Cloudflare-tunnelled C2 (peter-secrets-diana-yukon.trycloudflare.com). The campaign targets multiple brands (Notepad++, Teams, FileZilla, etc.), includes several malicious domains, IPs and download URLs as IoCs, and likely delivers an infostealer or RAT.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
