Ransomware, Phishing

Steam forums used for ClickFix cryptominer attacks

In a report by Bleeping Computer, threat actors are exploiting Steam discussion forums to distribute cryptominers through a social engineering tactic known as ClickFix. Attackers create fake Steam accounts to post seemingly helpful solutions to users' technical problems.

These malicious posts instruct users to open PowerShell as an administrator and execute a command, which secretly downloads and runs the XMRig cryptominer. The PowerShell script disguises itself as a Windows optimization utility, performing fake maintenance tasks while disabling security features like TLS certificate validation and adding the malware's directory to Microsoft Defender exclusions. The miner is downloaded from msfconfig[.]icu and installed as system.exe, with a scheduled task created to ensure it runs on startup with SYSTEM privileges. This method bypasses some security protections because the user manually initiates the malicious command. Users are advised to never run commands from unknown sources on forums and to check for specific indicators of compromise, such as the 'C:WindowsBackground' directory and 'XMRig-' scheduled tasks. If detected, antivirus scans are recommended, and in severe cases, a full operating system reinstallation may be necessary due to the potential for further malicious activity.

Source: Bleeping Computer

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds