Australia Faces ClickFix Malware Campaign Targeting Organizations
The Australian Cyber Security Center (ACSC) has issued a warning about an ongoing malware campaign that utilizes a social engineering technique known as ClickFix to spread the Vidar Stealer malware.
In this attack, users are misled into executing harmful PowerShell commands via fake CAPTCHA prompts displayed on compromised WordPress websites. Once executed, the malware can steal sensitive information, including passwords and cryptocurrency details.
Organizations across Australia, particularly those with infrastructure entities, are at risk. The impact of this attack can lead to significant data breaches and financial losses.
To protect against this threat, the ACSC advises organizations to restrict PowerShell execution, implement application allow-listing, and ensure WordPress sites are updated and secure.
Given the nature and scope of these attacks, the risk level is classified as High. Stay vigilant and educate users on recognizing suspicious online prompts to mitigate risks.
Source: View Original Report
