{"id":5042,"date":"2025-07-02T10:03:41","date_gmt":"2025-07-02T10:03:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/02\/kimsuky-hackers-using-clickfix-technique-to-execute-malicious-scripts-on-victim-machines\/"},"modified":"2025-07-02T10:03:41","modified_gmt":"2025-07-02T10:03:41","slug":"kimsuky-hackers-using-clickfix-technique-to-execute-malicious-scripts-on-victim-machines","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/02\/kimsuky-hackers-using-clickfix-technique-to-execute-malicious-scripts-on-victim-machines\/","title":{"rendered":"Kimsuky Hackers Using ClickFix Technique to Execute Malicious Scripts on Victim Machines"},"content":{"rendered":"<p>    Kimsuky Hackers Using ClickFix Technique to Execute Malicious Scripts on Victim Machines<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The notorious North Korean threat group Kimsuky has adopted a sophisticated social engineering tactic known as \u201cClickFix\u201d to deceive users into executing malicious scripts on their own systems.<\/p>\n<p>Originally introduced by Proofpoint researchers in April 2024, this deceptive technique tricks victims into believing they need to troubleshoot browser errors or verify security documents, ultimately leading them to unknowingly participate in their own compromise through manual code execution.<\/p>\n<p>The ClickFix methodology represents a significant evolution in psychological manipulation tactics, disguising malicious commands as legitimate troubleshooting procedures.<\/p>\n<p>Victims encounter fake error messages that appear to originate from trusted sources like Google Chrome, prompting them to copy and paste seemingly innocent code into <a href=\"https:\/\/cybersecuritynews.com\/new-koiloader-abuses-powershell-scripts\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> consoles.<\/p>\n<p>This approach effectively bypasses traditional security measures by exploiting human behavior rather than technical vulnerabilities, making detection significantly more challenging for conventional endpoint protection systems.<\/p>\n<p>Genians analysts <a href=\"https:\/\/www.genians.co.kr\/en\/blog\/threat_intelligence\/suky-castle\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> multiple attack campaigns throughout 2025 where Kimsuky operatives successfully deployed ClickFix tactics against high-value targets in South Korea.<\/p>\n<p>The security researchers observed the group targeting diplomacy and national security experts through sophisticated spear-phishing operations, demonstrating the technique\u2019s effectiveness in circumventing endpoint protection systems.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYZuHjoStsZRaYR6g4ELjDW6_TQ86lyJ_J4cKsDmiJa5SfNKlSPkXNevVsXxQSfNrEIeWH-n0i8jjH0Ve0C-CZ3Z2DNb0PHD-3qNytBt3kpWIlttJzFyeraHIDIKnCKf40NOWSTCY3to9ksVRMc7V3xYkXnP5AD1jWbSUHmXpCCMPJ9m6enanj75PH1lU\/s16000\/Attack%2520Scenario%2520%28Source%2520-%2520Genians%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Attack Scenario (Source \u2013 Genians)<\/figcaption><\/figure>\n<\/div>\n<p>The campaigns have evolved from simple VBS-based attacks to more sophisticated PowerShell implementations, showing continuous adaptation to defensive countermeasures.<\/p>\n<p>Recent investigations revealed that Kimsuky has integrated <a href=\"https:\/\/cybersecuritynews.com\/clickfix-technique-to-deliver-eddiestealer-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">ClickFix<\/a> into their ongoing \u201cBabyShark\u201d threat activity, utilizing multilingual instruction manuals in English, French, German, Japanese, Korean, Russian, and Chinese.<\/p>\n<p>The attackers impersonate legitimate entities, including government officials, news correspondents, and security personnel, to establish trust before delivering malicious payloads through encrypted archives or deceptive websites designed to mimic authentic portals and services.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Advanced Obfuscation and Persistence Mechanisms<\/strong><\/h2>\n<p>The technical sophistication of Kimsuky\u2019s ClickFix implementation demonstrates remarkable advancement in evasion techniques designed to circumvent modern security solutions.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhoq53aKWqTi4mJCRTPaLrUp99iQKg737WB08W_sxP5F4O29IuhATKsUFxepZ5wZ25oAXtMb-NHSirExcKj9L0K0sLaznegu-8czIbkq4eQFy-k5vI34TNW3zKuOF5TLVat1XJnZBf9G7AgPw6D0SqGHNebMLc77r5sAUD5HwQ1TDq4ZumPqdhMqovm8Sc\/s16000\/ClickFix%2520Popup%2520Message%2520%28Source%2520-%2520Genians%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">ClickFix Popup Message (Source \u2013 Genians)<\/figcaption><\/figure>\n<\/div>\n<p>The malware employs reverse-order string obfuscation to conceal malicious PowerShell commands, making visual inspection nearly impossible while maintaining full execution capability.<\/p>\n<p>A typical obfuscated command structure appears as:-<\/p>\n<pre class=\"wp-block-code\"><code>$value=\"tixe&amp;\"'atad-mrof\/trapitlum' epyTtnetnoC-\"\n$req_value=-join $value.ToCharArray()[-1..-$value. Length];\ncmd \/c $req_value;exit;<\/code><\/pre>\n<p>This technique stores malicious functionality in reversed strings, which are then reconstructed at runtime through PowerShell\u2019s character array manipulation functions.<\/p>\n<p>The malware further obscures its operations by inserting random numerical sequences like \u201c7539518426\u201d throughout command structures, utilizing Windows\u2019 native string replacement functionality to remove these markers during execution, effectively creating a dynamic decryption process.<\/p>\n<p>Once successfully deployed, the <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> establishes persistence through scheduled task creation and maintains communication with command-and-control servers using distinctive URI patterns including \u201cdemo.php?ccs=cin\u201d and \u201cdemo.php?ccs=cout\u201d.<\/p>\n<p>The infrastructure spans multiple countries and utilizes dynamic DNS services, with recent campaigns communicating through domains like konamo.xyz and raedom.store.<\/p>\n<p>The consistent version identifier \u201cVersion:RE4T-GT7J-KJ90-JB6F-VG5F\u201d observed across campaigns confirms the connection to Kimsuky\u2019s broader BabyShark operation.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=braodo_stealer&amp;utm_content=demo_1&amp;utm_term=250625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/kimsuky-hackers-using-clickfix-technique\/\">Kimsuky Hackers Using ClickFix Technique to Execute Malicious Scripts on Victim Machines<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/kimsuky-hackers-using-clickfix-technique\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kimsuky Hackers Using ClickFix Technique to Execute Malicious Scripts on Victim Machines The notorious North Korean threat group Kimsuky has adopted a sophisticated social engineering tactic known as \u201cClickFix\u201d to deceive users into executing malicious scripts on their own systems. Originally introduced by Proofpoint researchers in April 2024, this deceptive technique tricks victims into believing [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5042","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5042"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5042"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5042\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5042"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5042"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5042"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}