Technology

ClickFix attack discovered: Hackers spread harmful help on Steam

An attack campaign is currently underway in the Steam discussion forums, in which criminals pose as helpers for game and computer problems. Instead of harmless tips, they distribute instructions that infect devices with a cryptomining program.

Steam forums abused for click attacks

This affects users who respond to supposed solutions to crashes, lost items or other technical problems. That has Bleeping computer revealed. The attackers rely on a so-called ClickFix pattern. The victims are supposed to open PowerShell with administrator rights and run a command that acts like a repair measure. The command actually downloads an XMRig miner in the background and starts it on the computer.

Fake optimization fakes maintenance

The malicious script disguises itself as a Windows optimization tool named “msf utilityPC Opt”. It claims to delete temporary files, clear DNS cache, update drivers, check hard drive, disable startups, scan for malware, and repair system files, among other things. However, many of these functions are just a facade. The script displays fake progress messages and pauses for a few seconds at a time to appear serious. The actual malicious function is contained in a separate routine that switches off the validity of TLS certificates in advance and requires administrator rights.

Miner is installed permanently

With elevated rights, the script creates a folder under “C:WindowsBackground” and enters this as an exception in Microsoft Defender. It then attempts to terminate existing tasks or processes related to XMRig and delete possible configuration files. It then downloads the miner from an external server and saves it as “system.exe” in the folder. To ensure that the malware runs again every time Windows starts, the script sets up a scheduled task. This starts the file with system rights. It remains unclear whether this is only intended to eliminate remnants of previous installations or whether existing infections are being covered up.

This is how users protect themselves

Anyone who has run such a command should look for the “C:WindowsBackground” folder, a Defender exception for that path, and a scheduled task named “XMRig-“. If such traces are found, a complete virus scan is necessary. If in doubt, we recommend reinstalling the operating system because it is not possible to determine with certainty what other actions the malware has already carried out. In general, users should not execute PowerShell commands from forums if they come from unknown people. Even apparently helpful repair instructions can serve as a gateway for malware.

Recent Posts

Microsoft finally wants to fix Xbox download problems

Fluctuating rates, overloaded servers and frozen updates often plague Xbox users. Microsoft is now intervening…

52 minutes ago

Samsung Galaxy: New cell phone batteries with a step backwards in terms of longevity

Samsung is equipping its new folding smartphones with modern silicon-carbon batteries. This brings more capacity…

56 minutes ago

Exchange Online: Stupid email glitch sends too much into quarantine

Many Exchange Online users are struggling with unexpected problems. A bug suddenly moves harmless emails…

58 minutes ago

Microsoft solves Azure problem: Updates and Store are running again

After a widespread failure of the Azure infrastructure, central Windows services are working again. Users…

59 minutes ago

Ryzen 7 9800HX3D: AMD is probably planning an affordable gaming laptop CPU

AMD is reportedly preparing a new X3D laptop processor for demanding gamers. The upcoming CPU…

60 minutes ago

Netflix trial subscription: The free trial period is back in Germany

Netflix is ​​offering free trial subscriptions again in Germany after almost six years. The offer…

1 hour ago