Now, even Russia’s most elite hackers are using Clickfix to infect devices
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Ukraine's CERT has warned that Sandworm, an elite GRU-linked Russian hacking group, is now using the Clickfix social-engineering technique to compromise Ukrainian organizations. Clickfix tricks users into copying and pasting a PowerShell command disguised as a CAPTCHA verification, which then installs malicious VBS scripts and custom Sandworm malware packages such as GHETTOVIBE and SCOUTCURL. The campaign began in spring and has led to at least one confirmed network compromise. SCOUTCURL performs reconnaissance by collecting system info, browser data, and files, while GHETTOVIBE establishes persistence via the Startup directory. Previously associated mainly with financially motivated criminals, Clickfix is now being adopted by nation-state threat actors.