ClickFix attack discovered: Hackers spread harmful help on Steam

An attack campaign is currently underway in the Steam discussion forums, in which criminals pose as helpers for game and computer problems. Instead of harmless tips, they distribute instructions that infect devices with a cryptomining program.
Steam forums abused for click attacks
This affects users who respond to supposed solutions to crashes, lost items or other technical problems. That has Bleeping computer revealed. The attackers rely on a so-called ClickFix pattern. The victims are supposed to open PowerShell with administrator rights and run a command that acts like a repair measure. The command actually downloads an XMRig miner in the background and starts it on the computer.
Fake optimization fakes maintenance
The malicious script disguises itself as a Windows optimization tool named “msf utilityPC Opt”. It claims to delete temporary files, clear DNS cache, update drivers, check hard drive, disable startups, scan for malware, and repair system files, among other things. However, many of these functions are just a facade. The script displays fake progress messages and pauses for a few seconds at a time to appear serious. The actual malicious function is contained in a separate routine that switches off the validity of TLS certificates in advance and requires administrator rights.
Miner is installed permanently
With elevated rights, the script creates a folder under “C:WindowsBackground” and enters this as an exception in Microsoft Defender. It then attempts to terminate existing tasks or processes related to XMRig and delete possible configuration files. It then downloads the miner from an external server and saves it as “system.exe” in the folder. To ensure that the malware runs again every time Windows starts, the script sets up a scheduled task. This starts the file with system rights. It remains unclear whether this is only intended to eliminate remnants of previous installations or whether existing infections are being covered up.
This is how users protect themselves
Anyone who has run such a command should look for the “C:WindowsBackground” folder, a Defender exception for that path, and a scheduled task named “XMRig-“. If such traces are found, a complete virus scan is necessary. If in doubt, we recommend reinstalling the operating system because it is not possible to determine with certainty what other actions the malware has already carried out. In general, users should not execute PowerShell commands from forums if they come from unknown people. Even apparently helpful repair instructions can serve as a gateway for malware.
Research Snipers is currently covering all technology news including Google, Apple, Android, Xiaomi, Huawei, Samsung News, and More. Research Snipers has decade of experience in breaking technology news, covering latest trends in tech news, and recent developments.