Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting
Recent investigations by Hudson Rock's Threat Intelligence Team have identified a feedback loop in cybercrime involving stolen credentials from infostealer malware. These credentials allow attackers to repurpose legitimate business websites as platforms…
Recent investigations by Hudson Rock's Threat Intelligence Team have identified a feedback loop in cybercrime involving stolen credentials from infostealer malware. These credentials allow attackers to repurpose legitimate business websites as platforms for malware distribution.
The "ClickFix" method is a social engineering technique that manipulates users into executing harmful code. This attack initiates when users visit compromised sites that display counterfeit security alerts, mimicking tools like Google reCAPTCHA or browser error warnings.
Upon interacting with these counterfeit alerts, malicious JavaScript copies a PowerShell command to the user’s clipboard. The prompt then instructs users to press Windows+R and paste the "verification code," leading to the command's execution and subsequent malware installation, bypassing conventional security measures.
Analysis of data from the ClickFix Hunter platform, which monitors over 1,600 malicious domains, reveals that around 13% of these sites have administrative credentials exposed in infostealer logs. This indicates a pattern where compromised administrators inadvertently facilitate the hijacking of their websites for malware hosting.
These credentials allow attackers to repurpose legitimate business websites as platforms for malware distribution.
Stolen credentials include access to WordPress admin panels, cPanel controls, and other content management systems. For instance, the domain jrqsistemas.com hosts a ClickFix campaign, facilitated by previously stolen WordPress credentials.
These unauthorized accesses allow attackers to upload malicious scripts, converting legitimate business sites into malware distribution points. Similar occurrences have been identified on additional domains such as wo.cementah.com.
This cycle significantly expands the infrastructure for attacks, as more infections lead to more stolen credentials and subsequently more compromised websites. This creates a self-sustaining cycle that is difficult to disrupt due to its decentralized nature, with attackers leveraging numerous legitimate hosting providers.
The ClickFix Hunter platform, developed by ReliaQuest and Hudson Rock, aids in differentiating between malicious and compromised legitimate domains, thereby facilitating better remediation efforts.
Understanding and disrupting this infrastructure, particularly the credential theft feedback loop, is crucial for addressing these challenges. As cybersecurity defenses improve, attackers increasingly exploit human behavior through social engineering rather than technical vulnerabilities.
Based on reporting by Cyber Security News.
