HomeNewsNow even the most elite hackers in Russia use Clickfix to infect...

Now even the most elite hackers in Russia use Clickfix to infect devices.

One of the Russian government’s most elite hacker groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center warns.

Clickfix has emerged as an effective attack technique that attackers, primarily money-motivated criminals, have started using over the last year. Websites controlled by the attackers display a CAPTCHA that forces the visitor to copy a jumble of text and paste it into the terminal. The text contains scripts that, when entered, perform malicious actions, usually installing malware or exfiltrating sensitive data. Ukraine’s CERT said Wednesday that Sandworm, an advanced hacking unit within the GRU, Russia’s military intelligence arm, was now using the technique.

“GhettoVibe”, “ScoutCurl” and many others

The Clickfix attacks began in the spring and continued throughout the summer. The campaign resulted in at least one organization’s network being compromised when a connected device was found to be infected with FreakyPoll, the name of one of Sandworm’s custom malware packages. Ukrainian authorities discovered 10 compromised websites that displayed a PowerShell command in a fake CAPTCHA indicating that it needed to be passed to ensure that a real human was behind the keyboard of the visited device.

Once the user entered the script, they could install malicious Visual Basic scripts and other malware which then installed various Sandworm malware. Typically, the first malware executed was a reconnaissance program that collected information about the infected device. Machines deemed important would then receive malware that would hijack the system.

“The command, as an example, could be intended to load and save a VBS file in the startup directory,” a translated version of Tuesday’s notice states. “One of the variants of such a program was called GHETTOVIBE. At the next stage, in order to determine the importance of the cyberattack object, it is possible to load the SCOUTCURL software tool on the attacked computer, which is a PowerShell script that performs basic reconnaissance by collecting and exfiltrating information about the computer: basic characteristics, programs, files, Internet browser data, etc..”

Sandworm’s methodical approach, which involves using seemingly innocuous CAPTCHAs to bypass user awareness, underscores the evolving nature of cyber threats in the modern digital landscape. As nations like Ukraine bolster their cyber defenses, understanding and mitigating such sophisticated tactics is crucial. Analysts note that this attack vector, though not entirely new, has been refined by Sandworm to exploit human error effectively, marking a significant shift in their operational tactics.

For more detailed information on this evolving cyber threat, visit the source article: Here.

“`

Must Read
Related News

LEAVE A REPLY

Please enter your comment!
Please enter your name here