ClickFix Campaign Poses New Threat with Stealthy VBScript Payload
In recent developments within the cybersecurity landscape, a new campaign involving a technique known as ClickFix has been reported to perpetrate stealthy attacks on unsuspecting users by disguising a VBScript payload within the browser cache, cleverly masked as an innocuous image file. This innovative method ensures that the script resides on the victim’s device even before they are tricked into executing a command through the Windows Run dialog, significantly enhancing the effectiveness of the attack.
According to a revelation shared by Microsoft Threat Intelligence in a recent post on X dated October 3, a series of compromised websites has been leading visitors into the web of these attacks. The essence of the ClickFix technique lies in social engineering, where attackers leverage deception to manipulate victims into executing commands that originate from the attackers themselves, all while attempting to masquerade the process as a legitimate verification step.
The Mechanism Unveiled
The ClickFix campaign employs a deceptive tactic utilizing a pop-up that mimics a CAPTCHA—a familiar interface that users often encounter online. This fabricated CAPTCHA prompts users to open the Run program, instructing them to paste content from their clipboard and hit Enter. In a departure from conventional attack strategies, the technique does not rely on downloading the malicious payload post-execution. Instead, the payload is pre-fetched and stored within the browser cache, allowing for a more covert operation.
Microsoft notes that this pre-fetching significantly contributes to the stealthiness of the attack, enabling it to bypass the character limit that typically exists within the Run dialog. Essentially, the user needs only to locate and trigger a file that is already present on their device, an approach that minimizes the risk of detection and raises the stakes for victims.
The Technical Breakdown
Upon execution of the pasted command, it launches cmd.exe. This command-line interface searches the browser profile folder for cached files that begin with the prefix “f_,” checking each file’s size against an expected value. Instead of scanning cached content for specific markers—like many previous attacks—this operation relies on size matching. Once identified, the file is copied to a temporary folder and renamed with a .vbs extension before being executed through wscript.exe.
Once activated, the VBScript proceeds to gather detailed host information via Windows Management Instrumentation (WMI), subsequently fetching a PowerShell script that is executed with the execution policy sufficiently bypassed. This chain of events is meticulously orchestrated; later stages may involve compiling and loading additional code directly into memory, ultimately injecting it into the legitimate timeout.exe process to facilitate credential theft targeting both browsers and devices.
Ensuring Persistence and Control
To ensure a sustained presence on the victim’s device, the malware connects to servers controlled by the attackers, where it unpacks a copy of Python using the built-in tar.exe tool. Subsequently, a scheduled task is created to execute the Python payload via pythonw.exe, thereby establishing a foothold for the attackers that persists even after the system reboots.
In light of these alarming developments, Microsoft Defender Antivirus has classified the malicious execution commands under the names Trojan:Win32/ClickFix and Trojan:Win32/TermFix. To combat these threats, Microsoft has made several recommendations. Users are urged to enable cloud-delivered protection, network protection, application control, and PowerShell script-block logging to bolster their defenses against such attacks.
Recommended Defensive Measures
For cybersecurity analysts and defenders, Microsoft encourages a broader approach in threat hunting, advising individuals to monitor more than just download events. Attention should also be directed toward analyzing browser activity, unusual instances of WScript, PowerShell, and scheduled task activations. Moreover, the RunMRU registry key, which logs entries typed into the Run dialog, should be examined for suspicious activity. Microsoft has notably emphasized that legitimate CAPTCHA prompts should never request users to execute code, reinforcing the necessity for vigilance among users in identifying suspicious situations.
In summation, the ClickFix campaign illustrates an evolution in cyberattack methodologies, highlighting the critical need for enhanced awareness and proactive defenses against these sophisticated tactics. As technology continues to advance, both users and defenders must adapt and remain vigilant in safeguarding against emerging cyber threats.
