A cybersecurity researcher has developed FileFix, a new variation of the ClickFix social engineering attack that tricks users into executing malicious commands using Windows File Explorer. This advanced method has potential for widespread use in targeted malware and ransomware campaigns, including by state-sponsored threat actors. #mr.d0x #Kimsuky
Keypoints
- FileFix is a sophisticated evolution of the ClickFix attack that exploits Windows File Explorer.
- The attack involves phishing pages that trick users into pasting malicious commands into File Explorer.
- Threat actors can hide malicious PowerShell commands within dummy file paths to evade detection.
- FileFix has been used in ransomware, info-stealer, and remote access Trojan campaigns, including by North Korean hackers.
- The method is likely to be adopted widely due to its simplicity and effectiveness in executing malware.