Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Struggling families need help feeding pets as SNAP payments in doubt

November 8, 2025

Women in Mexico find safety in a feminist rideshare network

November 8, 2025

More Pakistani women are joining the country’s firefighters

November 7, 2025
Facebook X (Twitter) Instagram
Trending
  • Struggling families need help feeding pets as SNAP payments in doubt
  • Women in Mexico find safety in a feminist rideshare network
  • More Pakistani women are joining the country’s firefighters
  • Musk’s Net Worth Drops $10 Billion—And Tesla Shares Fall—Here’s Why
  • Here’s what to know about a study that raises questions about melatonin use and heart health
  • Trump’s Bungled Bet On Bitcoin Is Costing Him Bigtime
  • A Startup Was Their First-Ever Job—Now They’re The World’s Youngest Self Made Billionaires
  • Meet The Former Journalist Giving Away Billions
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Saturday, November 8
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » 100 Car Dealerships Hit by Supply Chain Attack
Cybersecurity

100 Car Dealerships Hit by Supply Chain Attack

By adminMarch 17, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 127


The websites of over 100 car dealerships were found serving malicious ClickFix code after a third-party domain was compromised in a supply chain attack.

As part of the compromise, a threat actor infected LES Automotive, a shared video service unique to dealerships, so that websites using the service would serve a ClickFix webpage to their visitors.

A ClickFix attack relies on malicious code on a webpage to display a prompt to the user, asking them to fix an error or perform a reCAPTCHA challenge, to prove they are human.

When the user clicks on the prompt, a malicious command is copied to the clipboard, and the user is also instructed to perform keyboard combinations that open the Windows Run prompt, paste the copied command into the prompt, and execute it.

The social engineering technique has been used for a couple of years, but started gaining popularity among cybercriminals and APTs last year, with a surge in adoption observed over the past several months.

In October 2024, HHS warned of Russian-speaking cybercriminals using the ClickFix technique in their attacks since at least April 2024.

ClickFix has been used to spread information stealers and other types of malware to users across various sectors. Recently, Microsoft warned of a widespread campaign targeting the hospitality industry.

As security researcher Randy McEoin warned, visitors of the websites of more than 100 auto dealerships using LES Automotive were targeted in a ClickFix campaign distributing the SectopRAT malware.

Advertisement. Scroll to continue reading.

The attack was using the fake reCAPTCHA variation of ClickFix, relying on PowerShell commands to deploy payloads on the victim’s machine, and ultimately infect them with the remote access trojan.

The JavaScript code designed to copy the malicious code to the clipboard, McEoin discovered, contained at least one comment in Russian. Users, he notes, would often be served a benign version of the script, which suggests that the injection was likely performed dynamically.

Related: Popular GitHub Action Targeted in Supply Chain Attack

Related: How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency Heist

Related: Cyberhaven Chrome Extension Hack Linked to Widening Supply Chain Campaign



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply

Don't Miss
Billionaires

Musk’s Net Worth Drops $10 Billion—And Tesla Shares Fall—Here’s Why

November 7, 2025

ToplineTesla shares declined more than 3% on Friday, cutting CEO Elon Musk’s fortune by $10…

Trump’s Bungled Bet On Bitcoin Is Costing Him Bigtime

November 7, 2025

A Startup Was Their First-Ever Job—Now They’re The World’s Youngest Self Made Billionaires

November 7, 2025

Meet The Former Journalist Giving Away Billions

November 7, 2025
Our Picks

Struggling families need help feeding pets as SNAP payments in doubt

November 8, 2025

Women in Mexico find safety in a feminist rideshare network

November 8, 2025

More Pakistani women are joining the country’s firefighters

November 7, 2025

Musk’s Net Worth Drops $10 Billion—And Tesla Shares Fall—Here’s Why

November 7, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.