ISSUE #001

Kopieren. Einfügen. Pivotieren.

An einem ansonsten ganz normalen Arbeitstag versuchte ein Angreifer, mithilfe einer neuen Variante der „ClickFix“-Technik einen identitätsbasierten Angriff auf die IT-Umgebung eines Luxusimmobilienentwicklers zu starten.

Analytics

USA + Europa

Immobilien

ClickFix variant

Enthalten

An einem ansonsten ganz normalen Arbeitstag fiel einem unserer MDR-Analysten ungewöhnliche Aktivität in der Umgebung eines Luxusimmobilienentwicklers auf. Ein Angreifer versuchte, mithilfe einer neuen Variante der ClickFix-Technik (MITRE T1204.004) einen identitätsbasierten Angriff zu starten.

Eine ruhige Umgebung kommt plötzlich zu Wort

Our MDR analysts build a baseline for every environment they monitor, because normal looks different from one company to the next. The real estate firm fell into the “usually quiet” category, which made a sudden cluster of detections for suspicious activity immediately stand out.

The ThreatDown EDR agent on one endpoint captured a command line that had executed through the Windows Run feature. Immediately, our MDR analyst wondered if it could be a ClickFix campaign, a social engineering attack that tricks users into copy-pasting a malicious command directly on their own machine. There’s no malicious file, no suspicious download. Just a regular user doing something they do every day.

But one detail didn’t fit. Typical ClickFix attacks rely on PowerShell, CMD, or mshta to execute HTML content. This command used rundll32. With years of experience tracking how threat actors operate, our analyst suspected the adversary had pivoted their method to evade the usual detection signatures, and moved to confirm it.

Der entscheidende Beweis

To confirm a ClickFix execution, our analyst needed proof that a person, not a script or a scheduled task, had run the command. The Run MRU registry key logs every command a user executes from the Windows Run dialog. If the alert’s command line was in there, the case was made.

The analyst opened a live session on the endpoint with the Active Response Shell, identified the logged-in account, mapped it to the right system profile through the ProfileList registry key, and enumerated that user’s Run MRU entries. The exact command line from the alert was there. A person had been socially engineered into pasting it and running it manually.

From there, our analyst moved straight to containment: malicious processes terminated, endpoint isolated, the attacker’s domain added to web protection, and the command pattern flagged in the anti-exploit engine. All of it inside the same window of minutes that opened with the first alert.

Our analyst then delivered a complete breakdown through the customer’s portal: how the attack unfolded, what actions had been taken, and what to do next. When the customer reviewed the findings, they confirmed everything the analyst had reconstructed, and moved on the recommendations without delay.

Identitätsangriff abgewehrt

ClickFix attacks are built for one outcome: stealing credentials that can be used in identity-based attacks. The script the user ran was a downloader. Its job was to contact the attacker’s server and install an information stealer that could quietly harvest credentials from the infected machine.

With valid credentials, the threat actor would have been able to access internal systems and steal sensitive financial details, property records, and information about active negotiations, while appearing as a legitimate user. The downstream exposure, including regulatory penalties, client notification obligations, and reputational damage, would have carried a steep price.

Because of MDR, that didn’t happen.

Für einen in den USA und Europa tätigen Entwickler von Luxusimmobilien ist Vertrauen der Motor des Geschäfts. Jede Transaktion hängt von Diskretion, dem richtigen Zeitpunkt und Vertrauen ab. Kunden erwarten, dass ihre finanziellen Daten, Immobilienunterlagen und Verhandlungen vertraulich behandelt werden. Ein einziger Verstoß könnte behördliche Untersuchungen nach sich ziehen, sensible Transaktionen offenlegen und Beziehungen zerstören, deren Aufbau Jahre gedauert hat.

In our business, client trust matters. Having ThreatDown MDR watching our environment at this level helps protect our reputation and keeps security from becoming a distraction.

IT Director, luxury real estate developer


Wiederaufbau

Vom ersten Signal bis zur vollständigen Übergabe

Signal

A cluster of detections

A cluster of correlated alerts in a low-noise environment stands out as soon as it lands in the analyst’s queue.

Vorahnung

A new variant?

The captured command suggests ClickFix, but some of the puzzle pieces are missing. The hypothesis: it’s a new variant designed to dodge the usual signatures.

Bestätigung

ClickFix confirmed

Our analyst identifies the active user and profile, and finds the exact command they ran. It’s ClickFix: the command was pasted into the Run dialog and executed manually.

Eindämmung

Termination!

Our analyst terminates the malicious processes, isolates the endpoint, blocks the attacker’s domain, and flags the command pattern in the anti-exploit engine.

Übergabe

Report delivered

A complete reconstruction lands in the customer’s portal explaining how the attack unfolded, the actions taken, and a clear remediation list: reimage the endpoint from a clean backup, rotate every credential on the machine, revoke active sessions and tokens, and enforce MFA across the environment.

No business fights alone.

Discover how our MDR heroes can help you.