Automatically translated.View original post

New ClickFix campaign detected

A new ClickFix campaign was detected, tricking the victim into changing the DNS value to install the malware.

As usual, a ClickFix campaign, or tricking the victim into following a fake error screen command, usually leads to the insertion of code to install the malware directly, but this campaign is something different.

According to a report by the website Cyber Security News, it mentions the detection of a ClickFix campaign in a new way that, instead of tricking the installation of traditional malware, leads to more technical changes on the victim's machine: modifying the Domain Name System or DNS settings on the victim's machine. After the victim completes the command by placing code on Run and pressing Enter, instead of downloading malware, the script runs cmd.exe to perform DNS Lookup (domain search) to the hacker's external server instead of the DNS Resolver. It is on the victim's system. This script will execute a Parse, Request, or Request sent out, especially in the Name: field of the DNS. In this field, it is not a real server name, but a payload file in step 2. If it is successfully downloaded, it will be installed immediately.

This technique allows hackers to use the DNS as a lightweight Staging Channel, confirming the accuracy of the target (Validation) before sending a heavier malware to the victim's machine. In addition, using this channel, which is a normal channel to communicate with the network, helps evade detection.

A research team from Microsoft Defender, the cybersecurity subsidiary of Microsoft, has also said that after downloading Payload in step 2 from Trigger by DNS Response, it will lead to chain malware embedding by downloading zipped compressed files. Inside, there is a Python Bundle file. If the file is opened, it will lead to Reconnaissance in the Host and Domain section, followed by Persistence in the victim's system by releasing VBScript scripts. Come down and create a shortcut called MonitoringService.lnk inside the Windows Startup folder to ensure that malware is restarted every time a new machine is booted.

And finally, it will be the last payload that is remotely controlled by the victim's machine, or the Remote Access Trojan (RAT), called ModeloRAT, installed on the victim's machine. The good news is that Windows Defender can be blocked. The malware is recorded in the database of this protection tool under the name Trojan: Win32 / ClickFix.R! ml.

# Trending # Lemon 8 Howtoo # lemon 8 diary # freedomhack # it

3/5 Edited to

... Read moreจากประสบการณ์ส่วนตัว ผมเคยเจอปัญหาความปลอดภัยคอมพิวเตอร์จากมัลแวร์ที่ใช้เทคนิคหลบซ่อนขั้นสูงแบบนี้ เมื่อหลายปีก่อนซอฟต์แวร์ป้องกันไวรัสไม่สามารถตรวจจับได้ทันที เพราะแฮกเกอร์ใช้ช่องทาง DNS ในการโหลดมัลแวร์ขั้นที่สอง ซึ่งถือเป็นวิธีการที่ฉลาดและซับซ้อนมาก เนื่องจาก DNS เป็นฟังก์ชันที่มีความจำเป็นอย่างยิ่งในการเชื่อมต่ออินเทอร์เน็ต ทำให้มัลแวร์สามารถหลีกเลี่ยงการถูกบล็อกโดยระบบรักษาความปลอดภัยทั่วไปได้ เทคนิคการใช้ DNS Lookup ในส่วนฟิลด์ Name: เพื่อส่งข้อมูลไฟล์มัลแวร์นั้น ทำให้วิธีตรวจจับด้วยระบบเดิมทำได้ยากขึ้นมาก เพราะข้อมูลมัลแวร์ถูกซ่อนในคำร้องขอ DNS ที่ดูเหมือนไม่มีพิษมีภัย ในฐานะผู้ใช้งานทั่วไป สิ่งที่ควรระวังคืออย่าไว้วางใจคำสั่งหรือหน้าต่างให้กดใส่โค้ดแปลก ๆ โดยเฉพาะอย่างยิ่งที่มาไม่ชัดเจนหรือมีลักษณะหลอกลวง นอกจากนี้ การตั้งค่าระบบ DNS ของเครื่องควรตรวจสอบอย่างสม่ำเสมอ ว่าถูกตั้งค่าโดยเราเองหรือแอปพลิเคชันที่น่าเชื่อถือ เพราะถ้าพบว่าถูกเปลี่ยนแบบไม่ทราบสาเหตุ อาจเป็นสัญญาณเตือนว่ามีมัลแวร์พยายามเข้าควบคุมเครื่องเรา ข้อมูลจากทีมวิจัย Microsoft Defender ที่แสดงให้เห็นการทำงานของมัลแวร์แบบลูกโซ่ การใช้ไฟล์ Zip และ Python Bundle เพื่อขยายอันตรายบนเครื่องนั้น ยิ่งเสริมให้เขตข้อมูลความปลอดภัยของเครื่องต้องเข้มงวดและอัปเดตโปรแกรมป้องกันไวรัสอยู่เสมอ หากได้ลองตรวจสอบประวัติ DNS Lookup ของเครื่องและพบคำขอที่ผิดปกติ เช่น ชื่อโดเมนแปลก ๆ หรือมีลักษณะเป็นข้อมูลที่เข้ารหัส ควรรีบหาข้อมูลและใช้ซอฟต์แวร์สแกนไวรัสทันที เนื่องจากแคมเปญ ClickFix รูปแบบใหม่นี้ใช้ความรู้ทางเทคนิคสูง จึงเหมาะกับการโจมตีแบบเจาะจงเป้าหมาย (Targeted Attack) ที่ต้องการข้อมูลหรือควบคุมเครื่องเหยื่อจากระยะไกล สุดท้าย การเรียนรู้และสดุดีเทคนิคการโจมตีใหม่ ๆ แบบนี้จะช่วยให้ผู้ใช้และองค์กรเพิ่มความระมัดระวังและมีมาตรการจัดการความปลอดภัยได้ดียิ่งขึ้น เช่น การจัดฝึกอบรมให้ความรู้เกี่ยวกับฟิชชิ่ง การตั้งค่าระบบเครือข่ายอย่างถูกต้อง และการติดตั้งโปรแกรมป้องกันมัลแวร์ที่มีประสิทธิภาพ แม้จะเป็นเรื่องซับซ้อน การป้องกันและความระมัดระวังอย่างต่อเนื่องเป็นวิธีที่ดีที่สุดในการลดความเสี่ยงด้านความปลอดภัยไซเบอร์

Related posts

🚀 Unidentified signal detected over the Gulf Coast
High-speed visuals. Deep-space energy. Precision-built execution. Pensacola X® operates at the intersection of AI-driven media, cinematic storytelling, and next-generation marketing—delivering content engineered to capture attention instantly and hold it. Nothing random. Nothing accidental.
PENSACOLA X®

PENSACOLA X®

1 like

Western horror campaign has started!
Marley is a half elf in a small ranch town, teaches the kids at the local school, helps at her father’s black smith shop, just the town sweet heart. On her friends birthday (day of the rodeo btw) there was a triple eclipse (this world had 3 moons) and the undead started rising. Now she’s got a walk
Arkaylix

Arkaylix

17 likes

#TiaKemp is standing on business after #ChriseanRock clapped back at her parenting advice! Tia made it clear she's not backing down — and if she sees something in the blogs, she's gonna speak on it. "You can't fight the world... l'ma comment and ain't nothing you can do
Stayrealbaddies

Stayrealbaddies

33 likes

⚠ BOTMOB SCAN DETECTED Bombast detected. Operator deployed: DJ BOT LA ROCK Link
appa juse

appa juse

1 like

how to handle being triggered in real time
Being triggered doesn’t mean you’re immature. It means your nervous system detected something it once learned was unsafe. The problem isn’t activation. The problem is reacting from activation. Most people try to fix the relationship, defend themselves, or explain their feelings while thei
Moonaisis_love

Moonaisis_love

19 likes

No lies detected 👊🏽👊🏽
Mizzotta

Mizzotta

23 likes

6 Desember 25 Aceh Tamiang 🥀Gak kebayang ini ketinggian banjirnya setinggi apa mobil mobil bisa ke angkat seperti ini dan Rumah rata sama tanah , Mencekam‼️ #banjir   #acehtamiang   #fyp   #foryou   #tiktok
CHANG MAYBELLE

CHANG MAYBELLE

2340 likes

Mental chess
💋cheilymar vega💋

💋cheilymar vega💋

8 likes

Comment your thoughts #strangerthings #strangerthings5 #strangerthingsfinale #conformitygate #netflix
Macy Ray

Macy Ray

161 likes

cozy home 🥹
all i think about while i’m at work everything is linked in my bio 🎀 #cozy #cozyhome #gamingsetup #newhome #gamergirl
mackenzie

mackenzie

5486 likes

Easiest approach for this scenario in RDR2 Story m
Easy money in an unfortunate accident. #reddeadredemption2clips #womenwhogame #momswhogame #rdr2 #gaming #gamingreels #rdr2gameplay
Liz 🖤

Liz 🖤

0 likes

App Talk: Free Stuff On Influenster
If you don’t have an account, I recommend you make one. Some people find it really hard to get campaigns, but it really just depends how frequent you put in reviews. I’ve had this account for a very long time and get a campaign here and there you do not have to do every campaign if you’re not inter
Savingwithcyn

Savingwithcyn

51 likes

🚨 BREAKING NEWS ALERT 🚨 This just in… travelers across California are reporting unbelievable room deals appearing on the map! 🗺️ Authorities confirm the source is none other than Studio 6 / Motel 6 — where comfortable extended-stay rooms and clean accommodations are now popping up at pric
Motel 6/ studio 6

Motel 6/ studio 6

0 likes

No lies detected
One of my most popular videos I’ve had on TikTok so I guess I will share it here too. #booktok #darkromance #darkromancebook
Samee Michelle

Samee Michelle

879 likes

My E.L.F Haul
Turning into an E.L.F. Girly 💄 I’ve been a Tarte lover for a while, but E.L.F has some amazing dupes! And you can’t beat the price 🏷️ #elfcosmetics #elfdupes #makeuphaul #girlythings
Chelsea Meador

Chelsea Meador

4346 likes

ANOMOLY DETECTED
#LimitlessSports #FRAMELOCK #alexcaruso #okcthunder
limitless sports

limitless sports

1 like

How to make your essay sound human 0% AI Detected
#essay #study #aitools #aihumanizer #edu
Self lock

Self lock

9 likes

✿˖° TextCortex: Your AI Writing Sidekick
‧°𐐪♡𐑂°‧₊ 💌 TextCortex is my go-to for working on essays, emails, and social posts because what really sets it apart is that it can learn your writing style too! First, optimize your setup: install the free version (10 daily creations, no card needed!) and try ZenoChat for instant ChatGPT-like help
peachiesuga ♡

peachiesuga ♡

65 likes

#new #breakingnews #republican #fyp #usa
Aaron Parnas Fans

Aaron Parnas Fans

1 like

Returning to NFL Universe 🤯 #nfluniverse #ultimatefootball #roblox #neoskittles
NeoSkittles

NeoSkittles

8 likes

I’m closing the bug hole.. that’s what she said😭
#helldivers2 #enjoy #funny
TOXIC_FADEAWAY

TOXIC_FADEAWAY

2 likes

Distortion Detected
Distortion Detected #clockworkmask #liminalspaces #backrooms #endless #vrchatworldshowcase
Clockworkmask

Clockworkmask

0 likes

IMPACT DETECTED #LimitlessSports #FRAMELOCK
limitless sports

limitless sports

0 likes

Sneak Peek: Canva’s Newest Tools Are Almost Here!
Canva recently dropped some game-changing updates at their Canva Create 2025 event. From the all-new Magic Studio (basically your creative BFF) to Canva Sheets (aesthetic spreadsheets are a thing now?!) — this update is HUGE. Whether you’re a designer, creator, planner, or spreadsheet-hater tur
Unrealtoreal

Unrealtoreal

62 likes

bullsh!t detected 👀
#merlin #arthurpendragon #cosplay #trend #bbcshow
Kayla J ⚔︎

Kayla J ⚔︎

78 likes

Day 2 of improving this painting based on y’all’s critiques! What should I fix next?? 👀 #painting #oilpainting #art #artist #portraitpainting #artistsoftiktok #tiktoklearningcampaign
Daphne Frizzle

Daphne Frizzle

2380 likes

Player Detected
You pressed start.. That was the first mistake... The screen glows soft and pale. Its edges flicker like it’s alive, but not in a friendly way. You thought it was just a game. You thought it could not see you. It can... The cursor blinks. Blinks in time with your heartbeat, or maybe it is
✝︎༺🏳️‍⚧️Umi🏳️‍⚧️༻✝︎

✝︎༺🏳️‍⚧️Umi🏳️‍⚧️༻✝︎

15 likes

Trump Defeats Letitia James and Her Lawfare Campaign Against Him in MASSIVE Legal Reversal #megynkelly #news #newtrend #fouryou #trendingvideo
Megyn Kelly

Megyn Kelly

89 likes

Maestro border #r6 #r6siege #rainbowsixsiege #rainbow6siege #schizosiege #siegex
Schizo6Siege

Schizo6Siege

0 likes

FIX YOUR GUT + recipes!
Try these recipes out and TUMMY GUT HEALTH to help you to count calories and see the percentages of bloating or fatigue, and symptoms that you could get! #guthealthyrecipes #guthealthfoods #gutrecipe #guthealingrecipes #bodytransformation
Callie Howe 🍰✨

Callie Howe 🍰✨

1 like

No lies detected.
#fortnite #vtuber
Lexi

Lexi

1 like

CONTENT CREATORS YOU NEED TO PAY ATTENTION!
Content creators you need to know how to take your pictures and how to record properly on your camera for quality content ! #contentcreatortips #brandambassadors #pr #iPhone #iphonetutorial #contentcreationhacks #lemon8creator #lemon8community #creator
Brikala R

Brikala R

308 likes

No windshield detected. $2 million
Mclaren Elva with no windshield 😎 #MclarenElva #Elva #Naples
Squilly

Squilly

1 like

Do You Really Have a Brand? Let’s Find Out.
Let’s be real—building a successful brand isn’t just about having a nice logo or a cute Instagram aesthetic. It’s about systems, strategy, and having the foundational assets in place to actually move your business forward. If you don’t have these essentials organized, then let me break it to you
Brianna Lavae - Business Coach

Brianna Lavae - Business Coach

5 likes

Secret hug power detected! 🐻💥
Secret hug power detected! 🐻💥 Save to CHARGE this snuggly energy! 🔋 @aboxfun #aboxfun #diy #hugpower #snugglecore
dcsummer

dcsummer

4 likes

Posture AI scan
Never been so easy got i posture scan with guided exercises #posture #posturecorrection #exercises #mobility
Jeniffer Pantoni | lifestyle🌸

Jeniffer Pantoni | lifestyle🌸

2 likes

Moving the Goalposts detected. You meet the standard → they raise it.
appa juse

appa juse

0 likes

Six Months Can Change Everything
There is no magic in months—but there is power in process. Six of them lined up with intention can move mountains most people are too scared to climb. Don’t count days, change them. Time doesn’t fix you—what you do inside of it does. This is the blueprint for those ready to trade comfort for charac
RoadToRiches

RoadToRiches

24 likes

sincerelynaturelife.com for Herbal Antibiotic Plus Capsules Your vagina is naturally acidic, semen is alkaline. When release happens inside you often, it can throw off your pH—leading to odor, BV, recurring yeast infections, or worse. I’m not saying this is the only cause, but it’s a common
Sincerelynature

Sincerelynature

11 likes

CHECK YT LINK IN BIO! #blackops7 #callofdutyblackops #campaign #bo7 #fypviralシ
IIM.NOOT.Q

IIM.NOOT.Q

0 likes

I hate when my baby is in trouble I had to let her get a lil fun in because my mom is a strict one when she gets mad 😂😭 #parentsoftiktok #fyp #supersus #gaming #donttell
🤍 Jas

🤍 Jas

0 likes

Forehead? Framed by Spirit, Not Filters
🪞 SPIRIT AIN’T BIRTH ME… THEY BLUEPRINTED ME. Y’all still blaming filters. But baby… this the default camera. 📸😭 No soft light. No blur. No AI enhancements. Just Spirit, bone structure, and natural lighting from my throne window 💅🏽✨ Y’all out here cropping, editing, spinning the photo
she posts in prophecy

she posts in prophecy

3 likes

Game master 5e first impression
I found this app and decided to give it a try. So far it’s available on both android and iPhone which is a plus. It has character sheets which seems amazing at first look but time will tell, and it seems to have everything at your fingertips. Also, there’s a free and a paid version with additional
Arkaylix

Arkaylix

3 likes

Special shout out to khajag, Graffix, Tyler and Greg in my last live😏😈
Angel_Scorn

Angel_Scorn

9 likes

This thing is wild
Kriss

Kriss

5 likes

See more