Tech »  Topic »  Hackers are abusing 'FileFix' technique to drop RATs during ransomware attacks

Hackers are abusing 'FileFix' technique to drop RATs during ransomware attacks


  • FileFix is a new technique to deploy malware, born out of ClickFix
  • It works by tricking users into pasting commands into File Explorer
  • The resulting compromise leads to Interlock encryptors

The dreaded ClickFix malware deployment technique has evolved, and the new variant - dubbed ‘FileFix’ - is being used in ransomware attacks.

ClickFix is a technique in which victims are presented with a fake problem (for example, a fake CAPTCHA, or a fake virus infection alert), and then provided with a fix. That “fix” usually revolves around pasting a command into the Windows Run program that was copied to the clipboard through the compromised website’s JavaScript.

The command, in most cases, is to download and run a piece of malware.

ClickFix fake error message malware spikes over 500%, takes second place as the most abused attack vectorWindows users warned of major security issue - here's why FileFix attack could be ...
Copyright of this story solely belongs to techradar.com . To see the full text click HERE