Still not smooth to study again 🚨
ClickFix attacks have resumed. Hackers use a fake full-screen Windows Update page to trick users into taking steps, especially pressing keyshortcuts or placing commands into the Run and Command Prompt channels, which cause victims to unknowingly run dangerous code themselves. All of this happens through a screen that looks like the real thing, so many may not be careful.
.
The scary thing is that around this time, hackers hide the payload of malware in PNG image files with Steganography techniques, embed data into pixel data, not just attach it to the end of the file like traditional methods, making it much harder for security systems to detect.
.
But don't be shocked that malware will bounce up and run easily. Even if PNG is embedded, it can't run anything. If you have never run a bootleg program, suspected files or dangerous scripts before, it's okay to just load photos and see them. It can't do anything by itself, except if the machine has been punched before, or you accidentally entered a dangerous web with a script. Once the web has a dangerous PNG, the script can pull the code from the image, and it can only open the web, but if you avoid risky web and do not open strange files, the chance of being stuck is considered. Very low.
.
For organizations, CMD or PowerShell can be set up, except for the admin, as well as checking unusual process chains such as explore.exe to call mshta.exe or powershell.exe, and check the command history in the Run channel through the Registry to check if something is wrong.
.
Source: bleepingcomputer
ในยุคที่เทคโนโลยีและการทำงานออนไลน์กลายเป็นส่วนหนึ่งของชีวิตประจำวัน เทคนิคการโจมตีทางไซเบอร์ก็มีการพัฒนารูปแบบขึ้นเรื่อยๆ เหมือนกรณี ClickFix ที่แฮกเกอร์รังสรรค์หน้าต่าง Windows Update ปลอมในลักษณะเต็มจอ เพื่อหลอกล่อผู้ใช้ให้ทำตามคำสั่งอันตราย เช่น การกดคีย์ลัดเพื่อรันคำสั่งผ่าน Run หรือ Command Prompt ทำให้มัลแวร์สามารถถูกติดตั้งในเครื่องได้อย่างรวดเร็วโดยที่ผู้ใช้ไม่รู้ตัว สิ่งที่น่าสนใจและทำให้เทคนิคนี้ยากต่อการตรวจจับ คือการใช้ Steganography หรือการฝังโค้ดอันตรายไว้ในภาพ PNG โดยตรง โดยแฮกเกอร์จะซ่อนข้อมูลโค้ดใน pixel data ของภาพ ทั้งนี้ต่างจากวิธีดั้งเดิมที่แค่แนบไฟล์ไว้ท้ายภาพ การฝังแบบนี้ทำให้ระบบความปลอดภัยปกติถูกหลอกและตรวจไม่พบมัลแวร์อย่างง่ายดาย อย่างไรก็ตาม การที่ไฟล์ PNG ถูกฝังโค้ดไว้ไม่ได้หมายความว่ามันจะรันได้เองหรือส่งผลกระทบทันที หากไม่มีโปรแกรมหรือสคริปต์ที่เปิดใช้งานโค้ดเหล่านั้นก่อน เช่น ผู้ใช้ไม่ได้รันไฟล์ต้องสงสัย หรือเครื่องไม่โดนเจาะล่วงหน้า แต่ถ้าหากเผลอเข้าเว็บที่มีสคริปต์อันตรายรวมถึง PNG ดังกล่าว สคริปต์เหล่านั้นสามารถโหลดโค้ดจากภาพขึ้นมารันได้ ดังนั้น การป้องกันตัวเองด้วยการไม่เปิดเว็บไซต์ที่ไม่น่าเชื่อถือ หลีกเลี่ยงการดาวน์โหลดไฟล์แปลกปลอม และไม่รันโปรแกรมเถื่อนหลังตลอดจึงเป็นสิ่งจำเป็น ในองค์กรที่มีการใช้งานร่วมกัน แนะนำให้ตั้งค่าสิทธิ์ไม่ให้พนักงานทั่วไปเข้าถึง Command Prompt (CMD) หรือ PowerShell ยกเว้นเฉพาะผู้ดูแลระบบเท่านั้น นอกจากนี้การตรวจสอบ process chain เช่น กระบวนการที่ผิดปกติจาก explorer.exe เรียก mshta.exe หรือ powershell.exe เป็นอีกวิธีที่ช่วยสังเกตพฤติกรรมแปลกๆ ของระบบ และยังควรตรวจประวัติคำสั่งในช่อง Run ผ่าน Registry เพื่อสืบค้นย้อนหลังความผิดปกติที่อาจเกิดขึ้น สำหรับประชาชนทั่วไป หากพบหน้าจอ Windows Update ที่ขอให้ทำตามขั้นตอนพิมพ์คำสั่งโดยไม่ทราบที่มา ควรสงสัยไว้ก่อนและตรวจสอบข้อมูลผ่านแหล่งข่าวหรือฝ่ายเทคนิค ก่อนดำเนินการใดๆ เพื่อป้องกันตัวจากการถูกโจมตีด้วยมัลแวร์ที่ซ่อนตัวในรูปภาพ และยังช่วยให้การรักษาความปลอดภัยบนโลกออนไลน์เป็นไปอย่างมีประสิทธิภาพยิ่งขึ้น

