Breaking Down a Modern ClickFix Attack
If you work in a SOC, it’s all too familiar at this point – a compromised endpoint alert comes into the alert queue, but the initial access vector isn’t immediately clear. As the analyst works backwards through the logs and timeline, a ClickFix attack begins to emerge. What initially looks like a user simply trying…
$ cat full-post