State-sponsored actors spotted using ClickFix hacking tool developed by criminals
- Proofpoint says multiple state-sponsored groups seen using ClickFix attack technique
- Russians, North Koreans, and Iranians all involved
- State-sponsored actors are mostly engaged in cyber-espionage
The ClickFix attack technique has gotten so popular that even state-sponsored threat actors are using it, research from Proofpoint claims, having observed at least three groups leveraging the method in the final quarter of 2024.
In an in-depth report, Proofpoint said it saw Kimsuky, MuddyWater, UNK_RemoteRogue, and APT28, all using ClickFix in their attack chains.
Kimsuky is a known North Korean threat actor, MuddyWater is Iranian, while UNK_RemoteRogue and APT28 are allegedly Russian. Aside from North Korea’s Lazarus Group, state-sponsored threat actors are mostly engaged in cyber-espionage, stealing sensitive information from diplomats, critical infrastructure organizations, think tanks, and similar organizations from adversary states.
No revolution
“The incorporation of ClickFix is not revolutionizing the campaigns carried out by TA427, TA450, UNK_RemoteRogue, and TA422 but instead is replacing the installation and execution stages in existing infection chains,” Proofpoint explained.
ClickFix has been making headlines for months now. It is a social engineering tactic similar to ancient “You’ve got a virus” popups that used to plague internet sites two decades ago.
Originally, the popup would invite the visitor to download and run an antivirus program which was, in fact, just malware.
When the industry addressed this attack by striking the infrastructure, crooks pivoted to leaving a phone number for alleged IT support.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Victims calling this number would be tricked into installing remote desktop programs, giving crooks the ability to download and run malware on their devices.
The ClickFix attack takes this method and gives it a unique spin. It still starts with a popup but sometimes the victims are also asked to “complete a CAPTCHA”, “verify their identity”, or similar. The process doesn’t require them clicking on a download button, but instead asks them to copy and paste a command in their Run program.
While it sounds far-fetched, it’s been quite successful, proven by nation-states’ adoption, as well.
Via The Hacker News
You might also like
Proofpoint says multiple state-sponsored groups seen using ClickFix attack technique Russians, North Koreans, and Iranians all involved State-sponsored actors are mostly engaged in cyber-espionage The ClickFix attack technique has gotten so popular that even state-sponsored threat actors are using it, research from Proofpoint claims, having observed at least three groups…
Recent Posts
- How to watch the World Cup Final ‘66 In Colour for *FREE*
- ‘Elon Musk said he thinks humanoid robots will be in many homes in three years, and I agree with him.’ I sat down with Jake Dyson to hear his predictions for AI and robotics in your home — and why you shouldn’t throw out your stick vac just yet
- LaCie 8big Pro5 review: I tested LaCie’s huge 256TB DAS solution, and it’s ideal for 8K video editing but it comes with a price tag that’s just as big
- EA’s Star Wars Zero Company drops August 27
- Amazon Prime members can already get $135 in free perks ahead of Prime Day 2026 — here are 7 freebies to claim right now
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023