Introducing Cavalier’s New Threat Feeds: Deep Dive into ClickFix Monitoring

We are thrilled to introduce three new Threat Feed modules in Cavalier: C2 Data, ClickFix, and PhaaS (Phishing-as-a-service). Together, they give security teams comprehensive visibility into active attacker infrastructure – from infostealer command-and-control (C2) servers to malicious ClickFix pages executing clipboard injection, to turnkey Phishing-as-a-service (PhaaS) kits targeting corporate credentials.

Overview of the Threat Feeds monitoring options
Overview of the new Threat Feeds monitoring options available inside Cavalier, including C2 Intelligence, ClickFix Monitor, and PhaaS Feed.

What’s New: ClickFix Monitor

The new ClickFix module provides critical visibility into malicious websites that use fake verification pages, CAPTCHA prompts, and clipboard injection techniques to trick users into executing malicious commands.

Inside Cavalier, you can seamlessly review:

  • Detected ClickFix sites
  • Clipboard injection and CAPTCHA indicators
  • Injected command payloads
  • Before-and-after interaction screenshots
  • Domain records and associated URLs
  • Date filtering and export options
Overview of recently flagged clickfix servers
A high-level overview of recently flagged ClickFix servers and domains identified within the Cavalier platform.

Analyzing Payloads and Deceptive Lures

With ClickFix lures becoming increasingly sophisticated, it is vital to understand the exact mechanisms threat actors are using to deceive employees. Cavalier allows you to investigate flagged sites, view the copied commands presented to victims, and examine visual evidence of the attack.

Details of payload and before/after captcha interaction
Detailed analysis showing a malicious clipboard payload alongside a before-and-after comparison of a fake CAPTCHA interaction hosted on solaric.com.ph.

Uncovering Initial Access: The Infostealer Connection

Perhaps the most powerful capability of the ClickFix monitor is its integration with Infostealer credential telemetry linked to the hosting platform. This pinpoints compromised employee or user credentials that enabled attackers to gain initial access to the server, explaining how a legitimate business domain became a host for malware.

Hudson Rock infostealer credentials associated with solaric.com.ph
Hudson Rock cybercrime intelligence revealing infostealer credentials associated with solaric.com.ph’s WordPress admin panel. This initial infection on a user’s computer directly led to the website being hacked and weaponized to deliver ClickFix.

Case Study: The Artlist Breach

We’ve previously documented how legitimate businesses turn into malware hosts, and a recent high-profile example perfectly illustrates this pipeline.

In our recent shared research on how an infostealer infection led to a sophisticated ClickFix campaign at Artlist, we traced the root cause of a compromised Artlist subdomain back to an infostealer infection from August 2023. A freelance developer unwittingly downloaded a pirated copy of Adobe Acrobat PRO DC, infecting their machine. This breach exposed highly privileged WordPress credentials belonging to a Senior Content Executive. Armed with valid, high-privilege access, threat actors were able to inject an advanced EtherHiding script into the blog, which dynamically routed visitors to a ClickFix payload.

Artlist delivering captcha and associated credentials
Visual evidence showing the compromised Artlist domain delivering a fake CAPTCHA payload, alongside the specific infostealer credentials that led to the initial breach.

With Cavalier’s new Threat Feeds, security teams can now instantly monitor these high-value, trusted domains that have been repurposed by threat actors. This capability pinpoints exactly where they are serving ClickFix prompts and simultaneously reveals the compromised credentials that facilitated the takeover.

Artlist in the ClickFix threat feeds feature
The compromised Artlist domain accurately flagged and detailed within Cavalier’s new ClickFix Threat Feeds feature.

Seamless API Integration for Proactive Defense

By feeding these surfaced ClickFix domains and indicators directly into your perimeter controls, firewalls, and DNS sinks, organizations can prevent social engineering attacks and block fake verification pages before employees can interact with or execute copied command payloads.

All datasets are fully accessible via REST API endpoints. Teams can utilize the GET /json/v3/threat-feeds/clickfix endpoint to retrieve detected sites, including domains, URLs, malicious indicators, clipboard activity, CAPTCHA detection, and screenshot evidence, or use the GET /json/v3/threat-feeds/clickfix/{domain} endpoint for specific record lookups.

Protect Your Organization from Imminent Intrusions

With our new Threat Feeds, cybersecurity teams can monitor live C2 infrastructure from infostealer campaigns, ClickFix networks, and PhaaS operations to proactively block malicious communications.

To learn more about how Hudson Rock protects companies from intrusions caused by info-stealer infections of employees, partners, and users, and how we enrich existing cybersecurity solutions with our cybercrime intelligence API, please schedule a call with us, here:
https://www.hudsonrock.com/schedule-demo

We also provide access to various free cybercrime intelligence tools that you can find here:
www.hudsonrock.com/free-tools

Thanks for reading, Rock Hudson Rock!
Follow us on LinkedIn: https://www.linkedin.com/company/hudson-rock
Follow us on Twitter: https://www.twitter.com/RockHudsonRock

The post Introducing Cavalier’s New Threat Feeds: Deep Dive into ClickFix Monitoring appeared first on InfoStealers.