• News/
  • https://www.bleepingcomputer.com/news/security/new-clickfix-attack-deploys-havoc-c2-via-microsoft-sharepoint/

New ClickFix attack deploys Havoc C2 via Microsoft Sharepoint

BleepingComputer
·
Lawrence Abrams
·
Published Mar 3, 2025
·
Updated

A newly uncovered ClickFix phishing campaign is tricking victims into executing malicious PowerShell commands that deploy the Havok post-exploitation framework for remote access to compromised devices. ClickFix is a social-engineering tactic that emerged last year, where threat actors create websites or phishing attachments that display fake errors and then prompt the user to click a button to fix them. Clicking the button will copy a malicious PowerShell command into the Windows clipboard, which users are then prompted to paste into a command prompt to "fix" the error. However, as expected, the malicious PowerShell command will instead execute a script hosted on a remote site that downloads and installs malware on the devices. In a new ClickFix campaign discovered by Fortinet's Fortiguard Labs, threat actors are sending phishing emails stating that a "restricted notice" is available to review and that recipients should open the attached HTML document ('Documents.html') to view it. When opened, the HTML displays a fake 0x8004de86 error, stating that it "Failed to connect to the "One Drive" cloud service" and that users must fix the error by updating the DNS cache manually.

Clicking the "How to fix" button will automatically copy a PowerShell command to the Windows clipboard and then display instructions on how to execute it. This PowerShell command will attempt to launch another PowerShell script hosted on the threat actor's SharePoint server. Fortiguard says that the scrip...

Read full article

Affected Software

3 affected components
Microsoft Windows
Microsoft Windows
Fortinet Fortiguard Labs
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly uncovered ClickFix phishing campaign that deploys the Havoc C2 post-exploitation framework via Microsoft SharePoint.

2

What security implications are discussed in the article?

The article highlights the risk of remote access to compromised devices through malicious PowerShell commands executed by victims.

3

What software is targeted by the ClickFix attacks?

The ClickFix attacks specifically target Microsoft Windows systems as part of the phishing campaign.

4

How does the ClickFix phishing campaign operate?

The campaign tricks victims into executing malicious PowerShell commands that install the Havoc framework.

5

What is the purpose of the Havoc post-exploitation framework mentioned in the article?

The Havoc framework is used for maintaining remote access to compromised devices after a successful attack.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
New ClickFix attack deploys Havoc C2 via Microsoft Sharepoint - SecAlerts