A new attack campaign is weaponizing trust in legitimate Ukrainian business websites to distribute a previously undocumented information stealer. The operation cleverly uses the "ClickFix" social engineering tactic, making users complicit in their own infection.

Research highlighted by The Hacker News reveals attackers have compromised real business sites and injected fake Cloudflare verification pages. When a user visits, the lure page automatically copies a malicious command to the clipboard and instructs the victim to paste it into a Windows Run dialog or terminal to "prove they are not a robot."

This manual execution downloads a loader, which then retrieves the primary stealer payload. The malware is designed to exfiltrate browser credentials, cryptocurrency wallets, session cookies, and other sensitive personal data.

The campaign's primary innovation is its exploitation of trust. By hosting lures on compromised, legitimate domains, attackers effectively bypass many reputation-based security filters that rely on blacklists. Furthermore, the ClickFix technique shifts the final execution step from the server to the user, evading numerous automated endpoint security tools that block direct malicious downloads.

This attack pattern is not region-specific and serves as a clear case study in modern social engineering. Effective defense requires a layered approach combining user education, website integrity, and technical controls:

  1. User Awareness and Training: Users must be trained to never paste commands from a website into a terminal or Run dialog. Any unexpected verification prompt should be treated as a major red flag and verified through a separate channel.
  2. Web Asset Integrity Monitoring: IT and web teams must implement continuous monitoring for unauthorized changes to websites, including content management systems and third-party scripts, to detect injected malicious content.
  3. Application Control Policies: Security administrators should enforce policies that restrict the execution of installer commands or unknown applications initiated from a browser, directly blocking the ClickFix step.

The emergence of this new stealer, distributed via trusted channels, underscores that domain reputation alone is insufficient security. A combined defense of vigilant users, well-maintained web assets, and hardened endpoints is essential to counter this evolving threat.


一場新型攻擊行動正利用受訪者對合法烏克蘭商業網站的信任,傳播一種前所未見的資訊竊密軟件。該行動巧妙運用「ClickFix」社交工程策略,使用戶在不知情下協助惡意軟件感染自身。

由《The Hacker News》報導的研究揭示,攻擊者已入侵真實商業網站並注入假冒的 Cloudflare 驗證頁面。當用戶訪問時,誘騙頁面會自動將惡意指令複製到剪貼簿,並指示受害者將其貼到 Windows「執行」對話框或終端機中,以「證明他們不是機器人」。

這項手動操作會下載一個加載程式,隨後獲取主要的竊密軟件載荷。該惡意軟件旨在竊取瀏覽器憑證、加密貨幣錢包、工作階段 Cookie 及其他敏感個人資料。

該行動的核心創新在於其對信任的濫用。透過在被入侵的合法網域上託管誘騙內容,攻擊者有效繞過許多依賴黑名單的聲譽型安全過濾器。此外,ClickFix 技術將最終執行步驟從伺服器轉移到用戶端,從而規避了許多會阻止直接惡意下載的自動化端點安全工具。

這種攻擊模式並非特定區域現象,是現代社交工程的清晰案例研究。有效防禦需採取結合用戶教育、網站完整性及技術控制的多層次方法:

  1. 用戶意識與培訓: 必須訓練用戶絕不將網站上的指令貼到終端機或「執行」對話框中。任何意外的驗證提示應視為重大警訊,並透過獨立管道核實。
  2. 網絡資產完整性監控: IT 與網絡團隊必須實施持續監控,以偵測網站(包括內容管理系統及第三方腳本)的未授權變更,從而發現注入的惡意內容。
  3. 應用程式控制策略: 安全管理員應強制實施限制從瀏覽器啟動安裝程式指令或未知應用程式的策略,直接阻斷 ClickFix 步驟。

這種新型竊密軟件透過可信渠道傳播的出現,凸顯了僅依賴網域信譽並不足以保障安全。結合警惕的用戶、維護良好的網絡資產以及強化的端點,構成抵禦此不斷演變威脅的必要防線。

新聞來源 / Original News Source