Researchers have identified a new ClickFix variant called LightPerlGirl involved in waterholing attacks on a travel website targeting users seeking holidays in the Galapagos. The malware evades detection by executing in memory and delivering Lumma infostealer, raising concerns about targeted and widespread cyber threats. #ClickFix #LummaInfostealer
Keypoints
- The LightPerlGirl variant of ClickFix was discovered on a compromised WordPress travel site.
- ClickFix employs social engineering and PowerShell evasion techniques to load malware silently.
- Visitors receive fake CAPTCHA prompts prompting them to run commands that execute malware in memory.
- The ultimate payload, Lumma infostealer, can lead to data theft and potential enterprise network access.
- Detection is challenging as ClickFix bypasses traditional security tools and affects high-value targets.