ClickFix Attacks: Convergence of Finger Protocol & Cloud Identity Abuse
Executive Summary
Key TTPs
-
Initial Access: Exploiting human error through social engineering, specifically fake "Verification" or "Browser Update" prompts on compromised legitimate websites.
-
Execution (Endpoint Stream): Tricking users into running
finger.execommands via the Windows Run dialog to bypass firewalls and download scripts. -
Execution (Identity Stream): Deceiving users into authenticating via the Microsoft Azure CLI application (ConsentFix) to grant persistent OAuth access.
-
Defense Evasion: Use of legacy protocols (Finger) to bypass proxy inspection and use of trusted first-party applications (Azure CLI) to evade conditional access policies.
Campaign Analysis
Targeting & Infrastructure
- Target Profile: Broad, with specific recent campaigns targeting Hospitality (Booking.com fraud), Transport/Logistics (fake manifest software), and Healthcare.
- Infrastructure: Compromised WordPress sites acting as Traffic Distribution Systems (TDS) and dedicated phishing domains hosting fake CAPTCHA pages. Actionable Intelligence
Relevant Terms
-
Finger Protocol: A legacy network protocol (TCP/79) exploited to fetch malicious scripts past firewalls that do not inspect non-HTTP traffic.
-
ConsentFix: A browser-native attack variant that tricks users into granting permissions to the Azure CLI app, allowing attackers to steal OAuth tokens without a password.
-
ClickFix: The overarching social engineering technique that tricks users into manually executing malicious commands (Paste-and-Run) by posing as legitimate error or verification prompts.
