PULSE NAME
ClickFix tactic: The Phantom Meet
WHITE Slavic Nation Empire AlienVault 2024-10-18 Modified: 2024-11-17
172
IOCs
HIGH VOLUME
This analysis explores the ClickFix social engineering tactic that emerged in 2024, focusing on a cluster impersonating Google Meet pages to distribute malware. The tactic tricks users into running malicious code by displaying fake error messages. The investigated cluster targets both Windows and macOS systems, spreading infostealers like Stealc, Rhadamanthys, and AMOS Stealer. The operation is linked to cybercrime groups 'Slavic Nation Empire' and 'Scamquerteo', sub-teams of larger cryptocurrency scam organizations. The report details the infection chain, infrastructure, and provides insights into the broader malware distribution ecosystem associated with these threat actors.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Stealc Rhadamanthys AMOS Stealer
Indicators of Compromise (3 / 172 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 51f8527e20dcb05ffd8586b853937a8a 2024-10-18
FileHash-MD5 ba0767946d9cac95fd727d7076c7fec1 2024-10-18
FileHash-MD5 e7959e4089c1993045e01cb9c3cbc6a5 2024-10-18