Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Pollution, development and climate change threaten Florida’s freshwater springs

August 29, 2025

With dawn of AI, talk of tech and religion merge for some

August 29, 2025

What is Labor Day. All you need to know

August 28, 2025
Facebook X (Twitter) Instagram
Trending
  • Pollution, development and climate change threaten Florida’s freshwater springs
  • With dawn of AI, talk of tech and religion merge for some
  • What is Labor Day. All you need to know
  • White House Reportedly Selects Jim O’Neill As CDC Director As Staffers Protest
  • Trump Administration Could Target Chicago With New Immigration Operation
  • Late Summer Box Office Ends With Whimper Without Blockbusters
  • It’ll Cost At Least $750 To Watch Every NFL Game This Season
  • Denver school district’s all-gender bathrooms violate Title IX, US Education Department says
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Friday, August 29
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » 100 Car Dealerships Hit by Supply Chain Attack
Cybersecurity

100 Car Dealerships Hit by Supply Chain Attack

adminBy adminMarch 17, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 78


The websites of over 100 car dealerships were found serving malicious ClickFix code after a third-party domain was compromised in a supply chain attack.

As part of the compromise, a threat actor infected LES Automotive, a shared video service unique to dealerships, so that websites using the service would serve a ClickFix webpage to their visitors.

A ClickFix attack relies on malicious code on a webpage to display a prompt to the user, asking them to fix an error or perform a reCAPTCHA challenge, to prove they are human.

When the user clicks on the prompt, a malicious command is copied to the clipboard, and the user is also instructed to perform keyboard combinations that open the Windows Run prompt, paste the copied command into the prompt, and execute it.

The social engineering technique has been used for a couple of years, but started gaining popularity among cybercriminals and APTs last year, with a surge in adoption observed over the past several months.

In October 2024, HHS warned of Russian-speaking cybercriminals using the ClickFix technique in their attacks since at least April 2024.

ClickFix has been used to spread information stealers and other types of malware to users across various sectors. Recently, Microsoft warned of a widespread campaign targeting the hospitality industry.

As security researcher Randy McEoin warned, visitors of the websites of more than 100 auto dealerships using LES Automotive were targeted in a ClickFix campaign distributing the SectopRAT malware.

Advertisement. Scroll to continue reading.

The attack was using the fake reCAPTCHA variation of ClickFix, relying on PowerShell commands to deploy payloads on the victim’s machine, and ultimately infect them with the remote access trojan.

The JavaScript code designed to copy the malicious code to the clipboard, McEoin discovered, contained at least one comment in Russian. Users, he notes, would often be served a benign version of the script, which suggests that the injection was likely performed dynamically.

Related: Popular GitHub Action Targeted in Supply Chain Attack

Related: How Social Engineering Sparked a Billion-Dollar Supply Chain Cryptocurrency Heist

Related: Cyberhaven Chrome Extension Hack Linked to Widening Supply Chain Campaign



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

OnlyFans Billionaire’s Fortune Doubles Amid Sale Talks And $700 Million Dividend

August 22, 2025

OnlyFans, a NSFW social network for creators has become a cash cow for its owner…

Tennis Legend Roger Federer Is Now A Billionaire

August 22, 2025

Sam Altman Is Going After Elon Musk’s Empire, One Company At A Time

August 18, 2025

How A Berkeley Professor Built Billion-Dollar Companies In His Lab

August 10, 2025
Our Picks

Pollution, development and climate change threaten Florida’s freshwater springs

August 29, 2025

With dawn of AI, talk of tech and religion merge for some

August 29, 2025

What is Labor Day. All you need to know

August 28, 2025

White House Reportedly Selects Jim O’Neill As CDC Director As Staffers Protest

August 28, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.