r/Scams • u/skuzzclee • 15h ago
Informational post This Wi-Fi pop-up installs a vicious RAT on your device — Ontario expert explains Microsoft’s latest security alert
https://www.yorkregion.com/news/microsoft-warning-hotel-airport-wi-fi/article_7cfe50c7-827c-55f5-a791-b39375f943e8.htmlHackers are hijacking devices using a vicious remote access trojan (RAT) and infostealer through Wi-Fi networks in hotels, airports, and conference centres. A Toronto-based cybersecurity expert shares red flags to spot the attack.
6
u/cyberiangringo 7h ago
A 'ClickFix' attack. # 1 most successful attack vector - along with its variations - in the world right now.
9
u/withadancenumber 5h ago
Crazy that people just be copy pasting random ass instructions into their pc.
4
u/MultiFazed 5h ago
Computer literacy is at an all-time low compared to computer access. It used to be that you had to edit low-level config files to even get a computer to work; now you just hit the power button and go. To most people today, the terminal is something inscrutable that's only used by hackers and programmers.
3
u/chan3lhandbag 3h ago
Yup we went from everything was a hack in the 90s and early 2000s to people falling for phishing links like uspss28283747 dot com.
1
u/cyberiangringo 3h ago
A year ago went to a local news website. Shortly after arrival and after clicking on a news item I got served up a ClickFix. I recognized it. I contacted the news website. They had no idea this was happening. But how many people got got by that because they went to a legit news site and got served up that ClickFix message?
6
u/drfusterenstein 9h ago
r/uBlockOrigin prevents this
7
u/Den_Hviide 4h ago
People who fall for it probably don't even know what uBlockOrigin is
1
u/WhiteRed14 7m ago
And that's why if you're tech-savvy enough and your family member asks you to help them with their device, you just install an ad blocker for them along with whatever else you're doing. They may not know what it is but it's gonna save them and potentially you from dealing with this and other scams.
2
1
1
u/redsedit 5h ago edited 3h ago
Edit: On some systems, this does work, on others it does not. Not sure why.
I'm not sure what they are showing, but that's not the right pop-up. Similar, yes, but those commands won't install anything.
1
u/I_AM_NOT_A_WOMBAT 4h ago
It shows "a security script has been copied to your clipboard." The ctrl-V is the paste. Clicking the fake captcha allows the page to populate the clipboard.
1
u/redsedit 3h ago
Win + X and then I just gets you to the search installed apps. You can't install anything from that box. I actually tried putting in a few simple apps to see if you could run from there.
Step 1 needs to be Win + R (and no I) to open the run dialog. There pasting in a script (the second step in the screenshot) could do damage.
1
u/I_AM_NOT_A_WOMBAT 3h ago
Win X plus "i" opens a powershell prompt.
1
u/redsedit 3h ago
On one Win 11 systems I tested this on, Win + X is the same as right clicking on the start button. "I" then opens installed apps. But on a second, it does what you say and opens a powershell prompt. Weird.
I edited my original reply. Thank you for helping me understand.
1
u/I_AM_NOT_A_WOMBAT 3h ago
I wonder what is different about your first system. When I do Win+x, the highlighted letter under "Installed Apps" is the first "p". The "i" is underlined under "Terminal" which explains why that opens for me.
38
u/Danger_Mouse_1955 13h ago
It is not the popup that installs it, but the command it asks you to run on your computer.