Fiji CERT Alert: ClickFix Campaign Distributing Vidar Stealer Malware
Overview
Fiji CERT is advising government agencies, businesses, critical infrastructure operators, website administrators, and the public of an emerging social engineering technique known as ClickFix, which has been actively observed globally since early 2024.
The technique is being used to distribute malware, including the well-known Vidar Stealer information-stealing malware, through compromised legitimate websites and deceptive fake verification prompts.
International cybersecurity agencies, including the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), have identified ClickFix campaigns targeting infrastructure and legitimate business websites. Similar attack methods may affect organizations and internet users within Fiji and the Pacific region.
What is ClickFix?
ClickFix is a sophisticated social engineering attack that tricks users into manually executing malicious commands on their devices.
The attack commonly uses:
Fake CAPTCHA verification pages
Fraudulent “Verify you are human” prompts
Fake Cloudflare verification screens
Browser pop-ups instructing users to copy and run commands
Unlike traditional malware attacks, ClickFix relies on user interaction, allowing attackers to bypass some automated security protections.
How the Attack Works
The attack typically begins when attackers compromise a legitimate website, often through vulnerable WordPress plugins, themes, or weak administrative security.
Once compromised:
Malicious code is injected into the website.
Users visiting the website are redirected to a fake verification page.
A fraudulent CAPTCHA or Cloudflare verification prompt is displayed.
The malicious website silently copies an obfuscated PowerShell command to the user’s clipboard.
The user is instructed to paste and run the command with administrator privileges.
The command downloads and executes the Vidar Stealer malware.
This process enables malware delivery with minimal warning signs to the victim.
About Vidar Stealer Malware
Vidar Stealer is a well-known information stealing malware targeting primarily Windows systems.
Once installed, Vidar can steal:
Saved browser passwords
Authentication cookies
Cryptocurrency wallet information
Banking credentials
System information
Browser history
Session tokens
Other sensitive data
The malware may also facilitate follow-on cybercrime activity, including:
Ransomware deployment
Business Email Compromise (BEC)
Credential abuse
Financial fraud
Identity theft
Technical Behaviour Observed
Analysis of ClickFix activity shows that the malware uses several advanced defence-evasion techniques.
These include:
Obfuscated PowerShell commands
Self-deleting malware files
In-memory execution
Command-and-control (C2) communications
Use of legitimate platforms such as Telegram bots and Steam profiles as “dead drop” infrastructure
This behaviour makes detection and forensic analysis significantly more difficult.
Indicators of Suspicious Activity
Organizations should investigate immediately if users report:
Unexpected CAPTCHA or Cloudflare verification prompts
Requests to copy and paste commands into PowerShell
Browser prompts requesting administrative access
Suspicious PowerShell execution
Unusual outbound HTTP/S traffic
Credential theft incidents
Sudden browser session hijacking
Fiji CERT Recommended Mitigations
For Website Administrators
Secure WordPress Environments
Keep WordPress fully patched and updated.
Remove unused or unsupported plugins and themes.
Apply security updates immediately.
Enable Web Application Firewall (WAF) protections.
Restrict Script Execution
Limit unauthorized JavaScript execution.
Monitor for malicious iframe injections.
Restrict clipboard manipulation from web content.
Harden Internet-Facing Systems
Prioritize patching externally accessible applications.
Conduct regular vulnerability assessments.
Monitor web server integrity and logs.
For Organizations and Businesses
Restrict PowerShell Usage
Enforce PowerShell execution policies.
Prevent unauthorized scripts from running.
Restrict outbound PowerShell network connections.
Apply Least Privilege
Limit administrator privileges.
Prevent users from running commands as administrators unless necessary.
Enable Multi-Factor Authentication (MFA)
Implement phishing-resistant MFA for:
Administrative accounts
Remote access systems
Email services
Cloud platforms
Implement Network Protections
Filter malicious outbound traffic.
Use protective DNS services.
Monitor suspicious HTTP/S POST requests.
Maintain Secure Backups
Maintain regular offline backups.
Test restoration procedures regularly.
Security Awareness Guidance
Fiji CERT strongly advises all users:
Never copy and paste commands from websites.
Never run PowerShell commands provided through pop-ups or CAPTCHA pages.
Be cautious of unexpected “verification” requests.
Report suspicious websites or behaviour immediately.
User awareness remains one of the most effective defenses against ClickFix-style attacks.
Fiji CERT Advisory
Fiji CERT encourages all organizations, government agencies, ISPs, and businesses to review their security posture and remain vigilant against evolving social engineering attacks.
Cybercriminals are increasingly targeting users directly through deception rather than exploiting technical vulnerabilities alone.
Strong cybersecurity awareness, secure configuration management, and proactive monitoring remain critical to protecting Fiji’s digital infrastructure.
Report Suspicious Activity
Fiji CERT
Website: Fiji CERT
Email: fiji-cert@digitalfiji.gov.fj
Phone: +679 9921727
Stay vigilant. Think before you click. Never run commands from untrusted websites.