ClickFix: the fake Cloudflare prompt that asks you to paste a command and steals your passwords
Arctic Wolf Labs has detected a campaign that compromises websites of small Ukrainian businesses —a hair clinic, a bookshop, and tool and car retailers, among others— to show visitors a fake Cloudflare check. The page secretly copies a command to the clipboard and asks the user to press Windows + R, paste it and run it to “prove they’re not a robot”. That command downloads and installs Psychedelic, a new infostealer that steals passwords saved in Chrome, Edge, Brave, Opera and other browsers, session tokens and cryptocurrency wallets.
It’s not an isolated case. A CTM360 report has found more than 17,000 URLs infected with fake Cloudflare pages and identifies ClickFix as the most common way into company networks today, because it needs no exploit or attachment: convincing the victim is enough. Even a domain used as an example in technical documentation, third-party[.]com, referenced in more than 1,700 code repositories, has started showing this trick to Windows visitors. The technique is now sold as a subscription service, which explains how quickly it is spreading.
Tip from Soporte Informático 360
No legitimate website will ever ask you to open the Run dialog (Windows + R), PowerShell or Terminal to paste a command. If a verification check asks you to, close the page. In companies, it’s worth training staff about this trick and restricting PowerShell to those who really need it.
Source: The Hacker News. Summary prepared by our team for informational purposes.
Computer repair for home users
We repair desktops, laptops and mini PCs that won’t start, shut down, overheat or run slowly.