ChainCatcher report: Cybersecurity firm Moonlock Lab has reported that crypto hackers have recently upgraded their "ClickFix" attack method, impersonating venture capital firms to contact target users via social platforms and tricking them into executing malicious code to steal crypto assets. Attackers pose as fake VC firms such as SolidBit, MegaBit, and Lumax Capital, sending collaboration requests via LinkedIn and directing victims to fraudulent Zoom or Google Meet meeting links. These pages embed a fake Cloudflare "I'm not a robot" verification button; clicking it copies malicious commands to the clipboard and lures users to paste and execute them in a terminal, completing the attack. Researchers note that this method bypasses traditional security defenses by compelling victims to execute commands themselves. Meanwhile, hackers are also hijacking browser extensions to carry out attacks. John Tuckner, founder of cybersecurity company Annex Security, disclosed that the Chrome extension QuickLens, after changing ownership on February 1, released a new version two weeks later containing malicious scripts that trigger ClickFix attacks and steal user data. The extension had approximately 7,000 users and has since been removed from the store. The compromised extension scans for cryptocurrency wallet data and seed phrases, and harvests Gmail content, YouTube channel data, and website login or payment credentials.
ClickFix Attack Escalates: Hackers Impersonate VCs and Hijack Browser Extensions to Steal Crypto Assets
ChaincatcherShare
A new variant of Sybil attack, dubbed 'ClickFix,' is spreading, with hackers impersonating VCs such as SolidBit and Lumax Capital on LinkedIn. Victims are lured to fake Zoom links containing malicious Cloudflare-style verification buttons that copy harmful commands to the clipboard. Attackers also compromised the QuickLens Chrome extension to steal wallet data and login credentials. Reentrancy attack methods are suspected in some cases, as scripts siphon sensitive user information. The extension was removed after impacting 7,000 users.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.