Target Industry
Indiscriminate, opportunistic targeting.
Overview
There has been a new complex phishing campaign identified using the ClickFix technique which targets Microsoft SharePoint accounts. Threat actors use this method to deploy a modified version of Havoc Demon and the Microsoft Graph API to obscure command-and-control (C2) communications within trusted, well-known services.
Impact
The impact of the ClickFix phishing technique includes the theft of sensitive information such as personal data, financial details, and login credentials. It allows malware to infiltrate and compromise systems, leading to unauthorised access and control. The technique also enables the malware to spread within networks, increasing the risk of widespread infection and further attacks. Additionally, by using trusted services like SharePoint, ClickFix makes it difficult for traditional security measures to detect and block the malicious activities.
Exploitation
The ClickFix phishing technique is exploited by sending phishing emails that contain an HTML attachment. The attachment displays s a fake error message that tricks users into pasting a malicious PowerShell command into their terminal.
This command downloads and executes a PowerShell script from a SharePoint URL controlled by the attackers. The PowerShell script performs checks for analysis or monitored by security tools. If successful, it downloads a Python interpreter and a remote Python shellcode loader.
The loader then deploys a modified version of the Havoc Demon C2 framework using the Microsoft Graph API to communicate with attacker-controlled SharePoint files, blending malicious traffic with legitimate cloud service requests.
Containment, Mitigations & Remediations
It is highly recommended to verify the sender of the email by always double-checking the sender’s details. If the charges or invoice requests are unexpected contact the vendor through trusted channels. Awareness training would be beneficial to highlight these phishing campaigns.
Indicators of Compromise
Some Indicators of Compromise (IoCs) for this type of phishing campaign can be:
- Unusual Login Locations: Login attempts from unexpected geographical locations
- Multiple Failed Login Attempts: Repeated failed sign-ins, indicating attempts to access accounts using stolen credentials
- Unexpected Outbound Network Traffic: Unusual patterns in data leaving the network
- Changes in Account Behaviour: Anomalies in user account activity, such as accessing unusual files or services
- New Software Installations: Unplanned installations or updates, potentially indicating malicious software.
Threat Landscape
More than 3.7 million companies worldwide rely on Microsoft 365 products. Microsoft has detected an increase in cyber-attack campaigns that exploit legitimate file hosting services. Due to the complexity of the ClickFix campaign, it is a concerning threat because of its advanced capabilities and widespread use.
Threat Groups
The specific threat group behind this has not been publicly identified at the time of writing.
Further Information













