{"id":28608,"date":"2024-06-20T08:27:17","date_gmt":"2024-06-20T12:27:17","guid":{"rendered":"https:\/\/www.thundercloud.net\/infoave\/new\/?p=28608"},"modified":"2024-06-21T08:33:52","modified_gmt":"2024-06-21T12:33:52","slug":"warning-do-not-click-this-popup-if-you-see-it","status":"publish","type":"post","link":"https:\/\/www.thundercloud.net\/infoave\/new\/warning-do-not-click-this-popup-if-you-see-it\/","title":{"rendered":"WARNING: Do Not Click This Popup If You See It!"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif;\"><strong><span style=\"font-size: 36pt;\">WARNING: Do Not Click This Popup If You See It!<\/span><\/strong><\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full\" src=\"https:\/\/thundercloud.net\/infoave\/images\/2024\/clickfix1.png\" alt=\"WARNING: DO NOT CLICK THIS POPUP IF YOU SEE IT! Cloudeight InfoAve\" width=\"600\" height=\"464\" \/><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Hackers have devised a new, deceptive method to trick users into installing malware named ClickFix, according to cybersecurity firm <span style=\"text-decoration: underline;\"><a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/clipboard-compromise-powershell-self-pwn\" target=\"_blank\" rel=\"noopener\">Proofpoint<\/a><\/span>.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">This scheme involves enticing users with one-click fake fixes to common errors in popular programs such as Chrome, OneDrive, and Microsoft Word. Once users download and execute these \u201cfixes\u201d by clicking the &#8220;Copy fix&#8221; button, they unwittingly run a PowerShell or a Windows Run command that compromises their systems.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">This dialogue installs a \u201croot certificate\u201d to flush the DNS cache, remove the clipboard content, show a fake message, and install an additional remote PowerShell script that does an anti-VM check before the information-stealer is installed. Various hacker groups, including those responsible for ClearFake, allegedly use this method. Proofpoint details how hackers exploit jeopardized sites by incorporating a malicious script handed over by Binance\u2019s Smart Chain contract on the blockchain to spread malware and infect susceptible Windows computers.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">The script will perform a series of checks to see if your computer is an acceptable candidate before downloading more payloads. It doesn\u2019t end there since users also need to be aware of an email-based threat that uses HTML attachments with a Word look to them. These attachments will encourage users to download a \u201cWord Online\u201d extension to see the file.<\/span><\/p>\n<p><strong><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Spreading the Infection:<\/span><\/strong><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Proofpoint reveals that attackers exploit compromised websites to inject malicious scripts. These scripts, delivered through <span style=\"text-decoration: underline;\"><a href=\"https:\/\/www.binance.com\/en\/square\/post\/448884\" target=\"_blank\" rel=\"noopener\">Binance&#8217;s Smart Chain<\/a><\/span> contract on the blockchain, specifically target Windows machines.<\/span><\/p>\n<p><strong><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">Beyond Pop-Ups: The Email Threat<\/span><\/strong><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\">The ClickFix campaign isn&#8217;t limited to pop-ups. Users should also be cautious of emails containing HTML attachments disguised as Word documents. These emails often urge the recipient to download a &#8220;Word Online&#8221; extension to view the attachment, potentially leading to malware infection.<\/span><\/p>\n<p><strong><span style=\"font-family: helvetica, arial, sans-serif; font-size: 18pt;\">Helping You to Stay Safe<\/span><\/strong><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\"><strong>Don&#8217;t Trust Pop-Up &#8220;Fixes&#8221;:<\/strong> If you encounter error messages within an application, find solutions from the program&#8217;s official resources or support pages.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\"><strong>Beware of Suspicious Emails:<\/strong> Don&#8217;t open attachments from unknown senders, and be wary of emails urging you to download additional software.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\"><strong>Use Good Security Software:<\/strong> Use a good antivirus\/antimalware program, like <strong><span style=\"text-decoration: underline;\"><a href=\"https:\/\/thundercloud.net\/emsisoft\/\" target=\"_blank\" rel=\"noopener\">Emsisoft<\/a><\/span><\/strong>, and keep it up-to-date.<\/span><\/p>\n<p><span style=\"font-family: helvetica, arial, sans-serif; font-size: 14pt;\"><strong>Always be Vigilant.<\/strong> By being vigilant and practicing safe browsing habits, you can protect yourself from ClickFix and similar malware scams.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; WARNING: Do Not Click This Popup If You See It! Hackers have devised a new, deceptive method to trick users into installing malware named ClickFix, according to cybersecurity firm Proofpoint. This scheme involves enticing users with one-click fake fixes to common errors in popular programs such as Chrome, OneDrive, and Microsoft Word. Once users download and execute\u2026 <span class=\"read-more\"><a href=\"https:\/\/www.thundercloud.net\/infoave\/new\/warning-do-not-click-this-popup-if-you-see-it\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":13950,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4496,1678,1669,2641,1680,1656,1674,779],"tags":[],"_links":{"self":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/28608"}],"collection":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/comments?post=28608"}],"version-history":[{"count":3,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/28608\/revisions"}],"predecessor-version":[{"id":28613,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/28608\/revisions\/28613"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media\/13950"}],"wp:attachment":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media?parent=28608"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/categories?post=28608"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/tags?post=28608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}