ClickFix Campaign Exploits Fake LinkedIn VCs to Spread Malware Among Crypto and Web3 Experts
## Malware Campaign Targeting Cryptocurrency and Web3 Professionals
Malware Campaign Targeting Cryptocurrency and Web3 Professionals
A sophisticated malware campaign has been identified, targeting professionals in cryptocurrency and Web3 through fraudulent venture capital identities on LinkedIn. The operation utilizes advanced social engineering tactics, cross-platform payloads, and a fake CAPTCHA flow to deceive users into executing malicious commands.
Attackers impersonate executives from fictitious firms like SolidBit Capital, MegaBit, and Lumax Capital, using well-crafted LinkedIn profiles and personalized outreach messages. They engage with community leaders, project contributors, and founders, steering conversations toward scheduling a "funding" or "partnership" meeting. Victims are directed to Calendly pages that link to fake Zoom or Google Meet URLs hosted on attacker-controlled domains.
Technical Details of the ClickFix Campaign
The campaign uses a cloned conference or industry news page with a fake Cloudflare CAPTCHA overlay to deceive targets. The ClickFix process consists of three main steps:
Fake CAPTCHA: A seemingly legitimate bot check using a single checkbox. Clipboard Poisoning: JavaScript inserts an OS-specific command into the user's clipboard, either a PowerShell or bash command based on the User-Agent. Guided Terminal Execution: Users are instructed to paste the command into a terminal, reinforced by a countdown timer and animations.
The campaign employs a fileless loader model, allowing attackers to deploy additional malware without leaving detectable traces on disk. On Windows, a hidden PowerShell command executes a remote script, while on macOS, a multi-stage bash chain downloads and runs a Python payload. Both systems utilize obfuscated binaries to evade detection.
The campaign shows similarities with operations attributed to UNC1069, a financially motivated group linked to North Korea. These include the use of Zoom-lookalike domains, social engineering tactics on LinkedIn, and OS-specific command chains. However, definitive attribution remains unconfirmed.
They engage with community leaders, project contributors, and founders, steering conversations toward scheduling a "funding" or "partnership" meeting.
Professionals are advised to exercise caution with unsolicited investment offers and verify all aspects of potential partners. Key recommendations include:
Domain and Company Verification: Check registration dates and cross-reference team members for inconsistencies. Meeting Logistics Scrutiny: Use URL scanners and be wary of suspicious meeting links. Terminal Instructions Caution: Legitimate entities will not request terminal command execution for verification. Awareness of Urgency Tactics: Be cautious of pressure to act quickly or bypass standard procedures.
Type Value Context
Domain zoom[.]us07-web[.]us Fake Zoom page, hosts ClickFix payload
Domain zoom[.]07usweb[.]us Fake Zoom page, hosts MegaBit fake company site
Domain goog1e[.]us-meet[.]com Fake Google Meet page
Domain hedgeweeks[.]online C2 server; typosquat of Hedgeweek (hedgeweek.com)
Domain lumax[.]capital New campaign infrastructure
URL calendly[.]com/hureivemykhail/with-solidbit-meeting Calendly link used in social engineering
Based on reporting by GBHackers.
