ClickFix - freewebstatics
ClickFix - freewebstatics
ClickFix attacks are a sophisticated form of social engineering, leveraging the appearance of authenticity to manipulate users into executing malicious scripts. Office of Information Security.
Incident Overview
The SOC was alerted to a Potentially Unwanted Program (PUP) execution on a host device. This PUP was named client32.exe, which additionally flagged as a file that may be imitating a system file. Investigation of this alert revealed a base file path of "C:\Users\%USER%\AppData\Roaming\VFrTdT\client32.exe". This file belongs to the NetSupport Remote Monitoring and Management (RMM) tool. It is commonly used by threat actors to gain control of victim devices.