SiliconANGLE·4 min read·hard

ClickFix moves into the browser and onto WebDAV, Cisco Talos finds

D
Duncan Riley
ClickFix moves into the browser and onto WebDAV, Cisco Talos finds
AI Summary

Cisco Talos researchers have identified new 'ClickFix' cyberattack campaigns that bypass traditional operating system interactions by targeting web browsers directly. These attacks use malicious JavaScript to skim cryptocurrency and manipulate browser data without requiring the user to download files.

Why it matters

This evolution in attack methodology demonstrates a shift toward browser-based exploitation, making traditional email and file-based security measures less effective.

Dive DeeperCreate a free account to unlock

Cisco Systems Inc.’s Talos Threat Intelligence group today detailed two ClickFix campaigns that push the technique past the copy-and-paste PowerShell prompt it is known for, one that never touches the operating system at all and one that ends in a stealer plus whichever follow-on payload the operators choose to task.

ClickFix emerged in 2024 and has become known for one move: a page claiming some check has failed and offering a command for the visitor to paste into the Windows Run dialog or a Mac terminal. Having the target run the code sidesteps the download warnings and email filtering that catch attachments. The technique has spread quickly since, turning up last month in a fake OpenAI Codex installer aimed at Mac users that Cato Networks Ltd. documented.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in