Hackers use ClickFix to launch Havoc C2 with PowerShell via SharePoint

Cybersecurity researchers warn about a phishing campaign that uses ClickFix to distribute Havoc, hiding the malware in SharePoint and using the Microsoft Graph API to evade detection.

lunes, 3 de marzo de 2025 • 1 min read • Q2BSTUDIO Team

Company-Software-Apps

Cybersecurity researchers have detected a new phishing campaign that uses the ClickFix technique to distribute an open-source command and control (C2) framework called Havoc.

In this attack, the threat actor hides each stage of the malware behind a SharePoint site and employs a modified version of Havoc Demon along with the Microsoft Graph API to disguise C2 communications within trusted and widely known services.

This type of threat underscores the importance of having advanced and secure technological solutions to protect the integrity of business data and systems. At Q2BSTUDIO, we offer specialized services in development and technologies that enable companies to strengthen their security and optimize their operations with cutting-edge tools. Our team works on innovations that help mitigate risks and respond efficiently to potential cyber threats.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.