Security Affairs
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback|Australian Police Charge Two Over TeamPCP Credential Theft|Meta to Pay Up to $18B Over Teen Social Media Use|CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do|OpenAI banned Russian ChatGPT accounts backing covert influence operation|CISA Red Team Fully Compromised Two Critical Infrastructure Orgs|FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure|U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog|88 ID Verification Breaches Show the Cost of Collecting Identity Data|WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion|Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams|Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

FBI director Kash Patel’s brand website taken offline after malware reports

FBI director site went offline after a hack used a fake Cloudflare page to trick users into running a ClickFix attack that installed malware. The merchandise website of FBI director Kash Patel (basedapparel[.]com) was taken offline on Friday after reports that it had been compromised by hackers using it to spread malware. The malware was […]

FBI director

FBI director site went offline after a hack used a fake Cloudflare page to trick users into running a ClickFix attack that installed malware.

The merchandise website of FBI director Kash Patel (basedapparel[.]com) was taken offline on Friday after reports that it had been compromised by hackers using it to spread malware. The malware was discovered on Thursday by “big time nerd” user known as “debbie.”

Visitors were instructed to copy a code from the website and paste it into their computer’s terminal, a social engineering method known as a ClickFix attack. Once executed, the Mac-specific code would download and install malware on the device.

A ClickFix attack is a social engineering technique that manipulates users into running malicious commands themselves, typically by posing as a fix for a problem or verification step, ultimately leading to malware installation or system compromise.

“A website that sells merchandise related to FBI Director Kash Patel went offline Friday after a hack apparently tricked visitors into downloading malware.” reports the website Straight Arrow News. “Visitors were then prompted to copy a code from the website and paste it into the terminal on their computers, a social engineering technique known as a ClickFix attack. When entered, the code, designed specifically for Mac computers, would download and install malware onto the user’s devices.”

At this time, the site is still offline.

The researcher who goes online with the X handler WifiRumHam analyzed the compromised website. The e-store was using WordPress plug-in WooCommerce running a multi-part malware attack. A malicious plugin running on the site both steals payment data and targets macOS users with a fake Cloudflare CAPTCHA (“ClickFix”) that tricks them into running hidden malicious commands.

If executed, the commands download a script-based macOS stealer that avoids normal security protections and can steal browser data, passwords, and cryptocurrency wallet information. It also targets many popular browsers and wallet apps, collects the data, compresses it, and sends it to a remote server before deleting itself.

The campaign appears to be widespread, with similar infections seen across many websites.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, FBI director)

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)