ClickFix Malware: Windows App-V to Deploy Amatera Infostealer
A new cyberattack campaign known as ClickFix exploits social engineering and legitimate Windows tools to compromise systems with the Amatera information-stealer. Attackers use deceptive CAPTCHA pages to trick users into executing malicious code through the Windows Run dialog, bypassing traditional security filters. The malware specifically abuses Microsoft Application Virtualization (App-V) scripts to launch fileless attacks that hide within system memory. To evade detection, the threat actors retrieve configurations via Google Calendar and use steganography to conceal payloads inside image files. Once active, the Amatera software harvests sensitive data like passwords and banking credentials from web browsers. Experts recommend implementing administrative restrictions, enhanced PowerShell monitoring, and comprehensive user training to defend against these sophisticated living-off-the-land techniques.