
Fake Advisors, ClickFix, and Chrome Sync Spying
This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…
Cisco Talos reports a real, financially motivated campaign by a Russian-speaking group (UAT-11795) targeting organizations in the US and Europe. The attackers use a “ClickFix” social-engineering trick to get victims to run a command, which leads to downloading trojanized installers for trusted tools (like Zoom/WebEx) and then stealing credentials and cryptocurrency. The campaign also uses stealthy, memory-only tooling and unusual command-and-control methods to maintain access.
Cisco Talos tracked a financially motivated, Russian-speaking group identified as UAT-11795, active since at least June of last year. The group's initial access method relies on a ClickFix social engineering technique: a webpage entices the user to copy and run a command to "fix" an issue. That command stealthily downloads and executes a remotely hosted weaponized HTA file, which runs an embedded VBScript that drops a batch file into the user's application temporary folder.
From there, the infection chain proceeds to install trojanized installers for legitimate, trusted software such as Zoom, WebEx, MobaXterm, DBeaver, and FaceIT. These fake installers are staged on attacker-controlled domains. Once installed, the campaign deploys previously undocumented tools, including a remote access trojan and a PowerShell-based in-memory implant, to steal credentials, browser data, and cryptocurrency wallet assets. Talos also noted an unusual fallback command-and-control method using a Polygon smart contract, reflecting a high level of sophistication.
The attack succeeds by exploiting trust in everyday workflows. Employees are conditioned to follow on-screen instructions to resolve technical issues, and a prompt to run a command to "fix" a problem does not always register as suspicious. Similarly, requests to reinstall or update common conferencing and remote-access tools like Zoom or WebEx can seem routine, especially for remote and hybrid workers who rely on these tools daily. The use of legitimate, well-known software names as cover makes the trojanized installers more convincing, and reliance on the fact that an installer is signed can create false confidence that it is safe.
Organizations should train staff to treat any copy/paste command request from a website as high risk and to verify such requests through known IT channels before acting. Software installation should be restricted to approved sources, such as a company software portal or vetted vendor sites, with clear guidance to verify download origin when in doubt. Security teams should also avoid treating a signed installer as automatic proof of safety, and should be able to answer where a given binary came from as readily as whether a known vulnerability has been patched. Techniques referenced include T1204.001, T1204.002, and T1656.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
ClickFix entices a user to execute a command shown on a webpage in order to fix a supposed problem, but running it stealthily downloads and executes a weaponized HTA file that begins the infection chain.
The attackers used trojanized installers for well known tools including Zoom, WebEx, MobaXterm, DBeaver, and FaceIT to steal credentials and cryptocurrency.
Cisco Talos tracked a Russian-speaking, financially motivated actor identified as UAT-11795, active since at least June of last year.
No. Researchers noted that users should not assume a signed installer means a program is safe, since trojanized installers were used to deliver malware in this campaign.
Imagine a web page that says: "To continue, copy this command and run it." That’s the ClickFix trap. Cisco Talos saw a group called UAT-11795 use this ClickFix trick: your command secretly pulls down a weaponized HTA file, then installs trojanized Zoom or WebEx that quietly steals passwords and crypto. Here’s the catch: that installer can be signed and look totally legit. The only real tell is where it came from, some random download page, not our software center or the official vendor site. If any site tells you to copy a command or install Zoom, WebEx, or similar from anywhere but our approved sources, stop and send a screenshot to IT using our usual helpdesk channel.

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software…

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools…

Cisco Talos reports a real, financially motivated campaign where victims are tricked via a “ClickFix” style lure into running a command that downloads a…

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…