Cybersecurity researchers have uncovered a sophisticated social engineering campaign that impersonates Meta account suspension notifications to trick users into installing dangerous malware. This attack represents an evolution of the ClickFix family of threats, introducing new techniques that bypass traditional security awareness training.
## What is FileFix?
FileFix is an advanced variant of ClickFix attacks that manipulates users into executing malicious commands through their computer’s file system. Unlike traditional ClickFix methods that target Windows Run dialogs, FileFix exploits the Windows File Explorer address bar to execute harmful PowerShell commands.
Originally developed by red team researcher mr.d0x, this technique has been weaponized by cybercriminals, including the Interlock ransomware group, to distribute malware and remote access trojans.
## How the Attack Works
The current campaign, discovered by Acronis security researchers, uses a multi-language phishing website that mimics Meta’s official support communications. The attack follows these steps:
1. **Initial Deception**: Users receive fake Meta notifications claiming their account will be disabled within seven days unless they view an “incident report”
2. **Social Engineering**: The phishing page instructs victims to copy what appears to be a file path and paste it into File Explorer to access the supposed document
3. **Hidden Payload**: Instead of copying a harmless file path, users unknowingly copy a malicious PowerShell command disguised with extra spaces and fake directory information
4. **Steganography**: The attack uses advanced hiding techniques, embedding encrypted malware within innocent-looking JPG images hosted on legitimate platforms like Bitbucket
## Advanced Evasion Techniques
This FileFix variant employs several sophisticated methods to avoid detection:
– **Visual Deception**: Extra spaces in the malicious command ensure only the fake file path appears visible in the address bar
– **Steganographic Concealment**: Malware payloads are hidden inside seemingly harmless image files
– **Multi-Stage Execution**: The attack uses multiple PowerShell scripts to decrypt and deploy the final malware payload
## The StealC Infostealer Threat
The campaign ultimately delivers StealC malware, which targets sensitive information including:
– Browser credentials and authentication cookies (Chrome, Firefox, Opera)
– Messaging app credentials (Discord, Telegram)
– Cryptocurrency wallet data (Bitcoin, Ethereum, Exodus)
– Cloud service credentials (AWS, Azure)
– VPN and gaming platform accounts
– Desktop screenshots for reconnaissance
## Ongoing Evolution
Acronis researchers observed multiple campaign variants over a two-week period, indicating active development and testing by the attackers. This suggests either infrastructure preparation for larger-scale attacks or real-time campaign optimization based on success rates.
## Protection Recommendations
Security experts recommend organizations take immediate action:
– **Update Security Training**: Educate employees about FileFix and ClickFix attack methods
– **Implement Caution Protocols**: Train users to be suspicious of instructions requiring copying and pasting from websites into system dialogs
– **Deploy Advanced Detection**: Update security tools to recognize these evolving social engineering techniques
– **Verify Communications**: Always verify account-related notifications through official channels
As cybercriminals continue refining these social engineering tactics, organizations must stay ahead by updating their security awareness programs and implementing robust detection mechanisms to protect against these increasingly sophisticated threats.
