Gizmodo readers hit with ClickFix malware prompts after account compromise
Infosec buffs say Windows users could have been infected with a nasty trojan, while Mac users got off lightly
Veteran tech website Gizmodo confirmed a compromise on Saturday after readers reported ClickFix malware prompts appearing on article pages.
Users posted screenshots of fake CAPTCHA windows appearing on Gizmodo's site. The attack aims to fool users into running malicious code via their terminals.
According to Proofpoint threat researcher Tommy M, the attack was seemingly launched by an affiliate of ErrTraffic, a ClickFix-as-a-service program that allows attackers to deliver whichever malware they choose.
He said the ClickFix prompt was tailored to each user's OS. The Windows version attempted to install the NetSupport RAT malware, which abuses the legitimate NetSupport Manager tool to gain access to affected systems.
Darktrace saysNetSupport RAT can also be used to exfiltrate files from affected systems and to load additional payloads, such as other malware strains...
Copyright of this story solely belongs to theregister.com. To see the full text click HERE