Legitimate Software Used in New ClickFix Malware Campaign
ClickFix campaigns have been in the news before for their ability to turn ordinary user actions into serious intrusions. The latest campaign uses a fake fix prompt to lead victims toward a previously undocumented remote access trojan called CNCMachineRMS.
The attackers use the legitimate and signed IBM SPSS WinWrap Basic IDE software, which is normally used for scripting. They steer its scripting function towards malicious files, making it harder to spot the activity.
CNCMachineRMS has a range of capabilities that make it a versatile tool for remote administration. It includes an interactive shell, file manager, screen capture, local account backdoor, and seven persistence methods.