Target Industry

Indiscriminate, opportunistic targeting.

Overview

There has been a new complex phishing campaign identified using the ClickFix technique which targets Microsoft SharePoint accounts. Threat actors use this method to deploy a modified version of Havoc Demon and the Microsoft Graph API to obscure command-and-control (C2) communications within trusted, well-known services. 

Impact

The impact of the ClickFix phishing technique includes the theft of sensitive information such as personal data, financial details, and login credentials. It allows malware to infiltrate and compromise systems, leading to unauthorised access and control. The technique also enables the malware to spread within networks, increasing the risk of widespread infection and further attacks. Additionally, by using trusted services like SharePoint, ClickFix makes it difficult for traditional security measures to detect and block the malicious activities. 

Exploitation

The ClickFix phishing technique is exploited by sending phishing emails that contain an HTML attachment. The attachment displays s a fake error message that tricks users into pasting a malicious PowerShell command into their terminal. 

This command downloads and executes a PowerShell script from a SharePoint URL controlled by the attackers. The PowerShell script performs checks for analysis or monitored by security tools. If successful, it downloads a Python interpreter and a remote Python shellcode loader. 

The loader then deploys a modified version of the Havoc Demon C2 framework using the Microsoft Graph API to communicate with attacker-controlled SharePoint files, blending malicious traffic with legitimate cloud service requests. 

Containment, Mitigations & Remediations

It is highly recommended to verify the sender of the email by always double-checking the sender’s details. If the charges or invoice requests are unexpected contact the vendor through trusted channels. Awareness training would be beneficial to highlight these phishing campaigns. 

Indicators of Compromise

Some Indicators of Compromise (IoCs) for this type of phishing campaign can be: 

  • Unusual Login Locations: Login attempts from unexpected geographical locations 
  • Multiple Failed Login Attempts: Repeated failed sign-ins, indicating attempts to access accounts using stolen credentials 
  • Unexpected Outbound Network Traffic: Unusual patterns in data leaving the network 
  • Changes in Account Behaviour: Anomalies in user account activity, such as accessing unusual files or services 
  • New Software Installations: Unplanned installations or updates, potentially indicating malicious software. 

Threat Landscape

More than 3.7 million companies worldwide rely on Microsoft 365 products. Microsoft has detected an increase in cyber-attack campaigns that exploit legitimate file hosting services. Due to the complexity of the ClickFix campaign, it is a concerning threat because of its advanced capabilities and widespread use. 

Threat Groups

The specific threat group behind this has not been publicly identified at the time of writing. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content