ISSUE #001

Copy. Paste. Pivot.

On an otherwise ordinary workday, a threat actor attempted to set up an identity-based attack on a luxury real estate developer’s environment using a new variation of the ClickFix technique.

Analytics

US + Europe

Real estate

ClickFix variant

Contained

On an otherwise ordinary workday, unusual activity on a luxury real estate developer’s environment caught the eye of one of our MDR analysts. A threat actor was attempting to set up an identity-based attack using a new variation of the ClickFix technique (MITRE T1204.004).

A quiet environment suddenly speaks

Our MDR analysts build a baseline for every environment they monitor, because normal looks different from one company to the next. The real estate firm fell into the “usually quiet” category, which made a sudden cluster of detections for suspicious activity immediately stand out.

The ThreatDown EDR agent on one endpoint captured a command line that had executed through the Windows Run feature. Immediately, our MDR analyst wondered if it could be a ClickFix campaign, a social engineering attack that tricks users into copy-pasting a malicious command directly on their own machine. There’s no malicious file, no suspicious download. Just a regular user doing something they do every day.

But one detail didn’t fit. Typical ClickFix attacks rely on PowerShell, CMD, or mshta to execute HTML content. This command used rundll32. With years of experience tracking how threat actors operate, our analyst suspected the adversary had pivoted their method to evade the usual detection signatures, and moved to confirm it.

The smoking gun

To confirm a ClickFix execution, our analyst needed proof that a person, not a script or a scheduled task, had run the command. The Run MRU registry key logs every command a user executes from the Windows Run dialog. If the alert’s command line was in there, the case was made.

The analyst opened a live session on the endpoint with the Active Response Shell, identified the logged-in account, mapped it to the right system profile through the ProfileList registry key, and enumerated that user’s Run MRU entries. The exact command line from the alert was there. A person had been socially engineered into pasting it and running it manually.

From there, our analyst moved straight to containment: malicious processes terminated, endpoint isolated, the attacker’s domain added to web protection, and the command pattern flagged in the anti-exploit engine. All of it inside the same window of minutes that opened with the first alert.

Our analyst then delivered a complete breakdown through the customer’s portal: how the attack unfolded, what actions had been taken, and what to do next. When the customer reviewed the findings, they confirmed everything the analyst had reconstructed, and moved on the recommendations without delay.

Identity attack averted

ClickFix attacks are built for one outcome: stealing credentials that can be used in identity-based attacks. The script the user ran was a downloader. Its job was to contact the attacker’s server and install an information stealer that could quietly harvest credentials from the infected machine.

With valid credentials, the threat actor would have been able to access internal systems and steal sensitive financial details, property records, and information about active negotiations, while appearing as a legitimate user. The downstream exposure, including regulatory penalties, client notification obligations, and reputational damage, would have carried a steep price.

Because of MDR, that didn’t happen.

For a luxury real estate developer operating across the US and Europe, trust drives the business. Every transaction depends on discretion, timing, and confidence. Clients expect their financial details, property records, and negotiations to stay private. A single breach could trigger regulatory scrutiny, expose sensitive transactions, and fracture relationships that took years to build.

In our business, client trust matters. Having ThreatDown MDR watching our environment at this level helps protect our reputation and keeps security from becoming a distraction.

IT Director, luxury real estate developer


Reconstruction

From first signal to full handover

Signal

A cluster of detections

A cluster of correlated alerts in a low-noise environment stands out as soon as it lands in the analyst’s queue.

Hunch

A new variant?

The captured command suggests ClickFix, but some of the puzzle pieces are missing. The hypothesis: it’s a new variant designed to dodge the usual signatures.

Confirmation

ClickFix confirmed

Our analyst identifies the active user and profile, and finds the exact command they ran. It’s ClickFix: the command was pasted into the Run dialog and executed manually.

Containment

Termination!

Our analyst terminates the malicious processes, isolates the endpoint, blocks the attacker’s domain, and flags the command pattern in the anti-exploit engine.

Handover

Report delivered

A complete reconstruction lands in the customer’s portal explaining how the attack unfolded, the actions taken, and a clear remediation list: reimage the endpoint from a clean backup, rotate every credential on the machine, revoke active sessions and tokens, and enforce MFA across the environment.

No business fights alone.

Discover how our MDR heroes can help you.