🖥️Computerworld•較早收集於 2m
ClickFix 轉用 Windows Terminal 規避偵測

#phishing#clickfix#lolbin#defense-evasionwindows-terminalmicrosoftpowershellwindows-terminal7-zipmsbuild
💡釣魚經 Terminal 規避 Defender/訓練—保護 Windows AI 工作站。(28字)
⚡ 30-Second TL;DR
有什麼變化
攻擊者指示使用 Win+X → I 啟動 wt.exe,而非 Win+R Run
為什麼重要
此規避手法提升對 Windows 使用者的釣魚成功率,威脅 AI 開發環境資料。企業須更新訓練,超越 Run 對話框警示。強化端點偵測優化的迫切性。
下一步行動
更新安全訓練,禁止開發機器在 Windows Terminal 貼上指令。
誰應關注:Enterprise & Security Teams
關鍵要點
- •攻擊者指示使用 Win+X → I 啟動 wt.exe,而非 Win+R Run
- •從假 CAPTCHA/驗證頁貼上十六進位編碼 PowerShell
- •下載改名 7-Zip 解壓惡意軟體,新增排程任務及 Defender 排除
- •替代鏈:XOR 批次檔、經 MSBuild LOLBin 的 VBScript、瀏覽器程式碼注入
🧠 深度解析
背景與延伸:來自公開資料,非原文內容。引用 8 個來源。
🔑 增強重點摘要
- •ClickFix 活動最終部署 Lumma Stealer,該惡意軟體透過 QueueUserAPC() 技術注入 chrome.exe 和 msedge.exe,竊取瀏覽器 Web Data 和 Login Data 憑證。[1]
- •變體 CrashFix(2026 年 1 月)故意崩潰瀏覽器,使用 finger.exe 下載混淆 PowerShell 並部署 Python RAT,透過排程任務「SoftwareProtection」持久化,每 5 分鐘執行。[4]
- •另一變體濫用 DNS nslookup 命令,從自訂 DNS 伺服器提取並執行第二階段負載,避開系統預設解析器偵測。[2]
- •起源於 2024 年夏季,初期透過假 reCAPTCHA 頁面結合剪貼簿劫持,迅速擴散至釣魚和惡意廣告活動。[6][8]
🛠️ 技術深入
- •Lumma Stealer 部署至 C:\ProgramData\app_config\ctjb,使用 QueueUserAPC() 進行進程注入,針對高價值瀏覽器文物竊取並外洩至攻擊者基礎設施。[1]
- •CrashFix 命令:finger.exe 連線至 69.67.173.30 下載 charcode 負載,解碼後執行 script.ps1 (SHA-256: c76c0146407069fd4c271d6e1e03448c481f0970ddbe7042b31f552e37b55817),下載 ZIP 含 udp.pyw 和 run.exe (重命名 Python)。[4]
- •DNS 變體:nslookup 至硬編碼外部 DNS 伺服器,過濾 'Name:' 回應作為第二階段 PowerShell 負載,後續建立 LNK 檔案指向 VBScript 於 Startup 資料夾持久化。[2]
- •偵測規則:SIEM 監控 Event ID 4688 (powershell.exe 由 explorer.exe 產生)、Base64 編碼命令、WinX 資料夾存取 (Event ID 4663)、mshta.exe 或 finger.exe 由瀏覽器產生。[3][5]
🔮 前景展望AI analysis grounded in cited sources
ClickFix 將整合更多 LOLBin 如 certutil.exe 和 mshta.exe
歷史演進顯示攻擊者持續轉移至 Win+X、nslookup 和 finger.exe 等可信系統工具,以規避 Run 對話框和員工訓練偵測。
Lumma Stealer 活動將因 ClickFix 激增 50% 以上
Bitdefender 報告顯示假 CAPTCHA 活動驅動 Lumma 和 CastleLoader 爆發,結合社交工程使其成為高效傳播載體。
企業需部署 Win+X 啟動行為基線監控
Unit 42 和 Microsoft 偵測規則強調監控 explorer.exe 產生 PowerShell 及 WinX 資料夾活動,可有效阻擋此類變體。
⏳ 時間線
2024-07
ClickFix 技術首次被發現,透過假 reCAPTCHA 和剪貼簿劫持擴散
2025-03
Unit 42 報告 Win+X 變體用於分發 Havoc C2 框架
2026-01
Microsoft 揭露 CrashFix 變體,濫用 finger.exe 部署 Python RAT
2026-02
Microsoft 發現 DNS nslookup ClickFix 及 Windows Terminal 規避偵測活動
2026-02
Bitdefender 警告 Lumma Stealer 透過 ClickFix 假 CAPTCHA 活動激增
📎 來源 (8)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- securityaffairs.com — Microsoft Warns of Clickfix Campaign Exploiting Windows Terminal for Lumma Stealer
- thehackernews.com — Microsoft Discloses Dns Based Clickfix
- blog.cyberdesserts.com — What Is Clickfix Social Engineering Attack
- Microsoft — Clickfix Variant Crashfix Deploying Python Rat Trojan
- unit42.paloaltonetworks.com — Preventing Clickfix Attack Vector
- cybermaxx.com — Clickfix Explained How Threat Actors Use Clipboard Hijacking to Breach Systems
- sisainfosec.com — Critical Alerts Covering Clickfix Evolves AI Supply Chain Attacks and Enterprise Zero Days
- krebsonsecurity.com — Clickfix How to Infect Your Pc in Three Easy Steps
📰
AI 週報
閱讀本週精選 AI 大事摘要 →
👉相關動態
AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: Computerworld ↗
每週 AI 簡報
每週一封,可隨時退訂。