Fake Google and Cloudflare pages trick users into running malware themselves
Malwarebytes has mapped campaigns that use fake verification pages styled as Google and Cloudflare checks. The user is asked to copy a command and run it to "verify" that they are human. The technique is known as ClickFix, and it leads to the installation of several malware families, among them HijackLoader, StealC, Remus and Amatera Stealer.
What this means for your organisation
The attack sidesteps much of the technical defence because the user performs the action herself. The result is usually theft of passwords, browser sessions and tokens, which in turn gives the attacker access to mail, cloud services and business systems. For a Norwegian organisation this is a realistic route to account takeover and subsequent extortion, whatever the sector.
Berigo recommends
- Block or alert on use of the Windows Run dialog and PowerShell from ordinary user accounts wherever this is practical.
- Give staff one concrete rule: no legitimate website asks you to paste a command into your machine.
- Set up detection for new sessions from unknown devices, and make token revocation easy to trigger on suspicion.
- Rehearse the case where an employee reports having run such a command, so the response takes minutes rather than days.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch