ISSUE #001

Copiar. Pegar. Girar.

En una jornada laboral que, por lo demás, transcurría con normalidad, un ciberdelincuente intentó lanzar un ataque basado en la suplantación de identidad contra el entorno de una promotora inmobiliaria de lujo utilizando una nueva variante de la técnica ClickFix.

Analytics

EE. UU. + Europa

Inmobiliaria

ClickFix variant

Contenido

En una jornada laboral que, por lo demás, transcurría con normalidad, una actividad inusual en el entorno de una promotora inmobiliaria de lujo llamó la atención de uno de nuestros analistas de MDR. Un actor malicioso estaba intentando llevar a cabo un ataque basado en la identidad utilizando una nueva variante de la técnica ClickFix (MITRE T1204.004).

Un entorno tranquilo se hace oír de repente

Nuestros analistas de MDR establecen un punto de referencia para cada entorno que supervisan, ya que lo que se considera «normal» varía de una empresa a otra. La empresa inmobiliaria se clasificaba en la categoría de «normalmente tranquila», lo que hizo que un repentino aumento de detecciones de actividad sospechosa llamara la atención de inmediato.

The ThreatDown EDR agent on one endpoint captured a command line that had executed through the Windows Run feature. Immediately, our MDR analyst wondered if it could be a ClickFix campaign, a social engineering attack that tricks users into copy-pasting a malicious command directly on their own machine. There’s no malicious file, no suspicious download. Just a regular user doing something they do every day.

But one detail didn’t fit. Typical ClickFix attacks rely on PowerShell, CMD, or mshta to execute HTML content. This command used rundll32. With years of experience tracking how threat actors operate, our analyst suspected the adversary had pivoted their method to evade the usual detection signatures, and moved to confirm it.

La prueba irrefutable

To confirm a ClickFix execution, our analyst needed proof that a person, not a script or a scheduled task, had run the command. The Run MRU registry key logs every command a user executes from the Windows Run dialog. If the alert’s command line was in there, the case was made.

The analyst opened a live session on the endpoint with the Active Response Shell, identified the logged-in account, mapped it to the right system profile through the ProfileList registry key, and enumerated that user’s Run MRU entries. The exact command line from the alert was there. A person had been socially engineered into pasting it and running it manually.

From there, our analyst moved straight to containment: malicious processes terminated, endpoint isolated, the attacker’s domain added to web protection, and the command pattern flagged in the anti-exploit engine. All of it inside the same window of minutes that opened with the first alert.

Our analyst then delivered a complete breakdown through the customer’s portal: how the attack unfolded, what actions had been taken, and what to do next. When the customer reviewed the findings, they confirmed everything the analyst had reconstructed, and moved on the recommendations without delay.

Se ha evitado un ataque de suplantación de identidad

ClickFix attacks are built for one outcome: stealing credentials that can be used in identity-based attacks. The script the user ran was a downloader. Its job was to contact the attacker’s server and install an information stealer that could quietly harvest credentials from the infected machine.

With valid credentials, the threat actor would have been able to access internal systems and steal sensitive financial details, property records, and information about active negotiations, while appearing as a legitimate user. The downstream exposure, including regulatory penalties, client notification obligations, and reputational damage, would have carried a steep price.

Because of MDR, that didn’t happen.

Para una promotora inmobiliaria de lujo que opera en Estados Unidos y Europa, la confianza es el motor del negocio. Cada transacción depende de la discreción, la oportunidad y la confianza. Los clientes esperan que sus datos financieros, los registros de sus propiedades y las negociaciones se mantengan en la más estricta confidencialidad. Una sola infracción podría dar lugar a un escrutinio regulatorio, sacar a la luz transacciones sensibles y romper relaciones que han tardado años en construirse.

In our business, client trust matters. Having ThreatDown MDR watching our environment at this level helps protect our reputation and keeps security from becoming a distraction.

IT Director, luxury real estate developer


Reconstrucción

Desde la primera señal hasta el traspaso completo

Señal

Un conjunto de detecciones

Un conjunto de alertas correlacionadas en un entorno con poco ruido llama la atención en cuanto aparece en la cola del analista.

Corazonada

¿Una nueva variante?

El comando capturado apunta a ClickFix, pero faltan algunas piezas del rompecabezas. La hipótesis: se trata de una nueva variante diseñada para eludir las firmas habituales.

Confirmación

ClickFix confirmado

Our analyst identifies the active user and profile, and finds the exact command they ran. It’s ClickFix: the command was pasted into the Run dialog and executed manually.

Contención

¡Despido!

Our analyst terminates the malicious processes, isolates the endpoint, blocks the attacker’s domain, and flags the command pattern in the anti-exploit engine.

Entrega

Informe entregado

En el portal del cliente se publica un informe completo en el que se explica cómo se desarrolló el ataque, las medidas adoptadas y una lista clara de acciones correctivas: restaurar el terminal a partir de una copia de seguridad limpia, cambiar todas las credenciales del equipo, revocar las sesiones y los tokens activos, y aplicar la autenticación de dos factores (MFA) en todo el entorno.

No business fights alone.

Discover how our MDR heroes can help you.