ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Dark Reading reports two ClickFix social engineering campaigns abusing legitimate services to compromise organizations and maintain persistent access.
Dark Reading describes two separate attacks in which threat actors used the ClickFix social engineering tactic to compromise organizations. The campaigns abuse legitimate, trusted services to gain and maintain persistent access to victim environments. No specific victims, actors, or indicators were named in the available text.
- Two distinct campaigns leverage the ClickFix tactic
- Legitimate services are abused for stealth and persistence
- ClickFix lures users into running attacker-supplied commands
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at darkreading.com.