• News/
  • https://www.theregister.com/2025/09/16/filefix_attacks_facebook_security_alert/

FileFix attacks use fake Facebook security alerts to trick victims into running infostealers

The Register
·
Jessica Lyons
·
Published Sep 16, 2025
·
Updated

An attack called FileFix is masquerading as a Facebook security alert before ultimately dropping the widely used StealC infostealer and malware downloader on Windows machines. FileFix is a variation on ClickFix, a newish type of social-engineering technique first spotted last year that tricks victims into running malware on their own devices using fake fixes and login prompts. These types of attacks have surged by 517 percent in the past six months, according to researchers at antivirus and internet security software vendor ESET, making them second most common attack vector behind phishing. ClickFix typically asks the victim to perform a fake CAPTCHA test. FileFix tricks the user into copying and pasting a command into a file upload window or File Explorer, which after victims press Enter executes the payload(s) on their own machine. This beautiful house. These doors. It's an evasion technique. It's also a mark of a sophisticated attacker Acronis' Threat Research Unit discovered the FileFix attack in late August, and told The Register that it's the first in-the-wild example that doesn't strictly follow the original proof-of-concept (PoC) attack demonstrated by a researcher known as “mr.d0x” in July. "I've seen samples pop up on the 13th, which is a couple of days ago," Acronis senior researcher Eliad Kimhy told The Register, noting a burst of VirusTotal file submissions and phishing sites associated with this attack. "They keep evolving the infrastructure." The VirusTotal upl...

Read full article

Affected Software

1 affected component
ESET antivirus and internet security software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a cyber attack named FileFix that uses fake Facebook security alerts to install malware on victims' Windows machines.

2

What security implications are discussed in this article?

The article highlights the dangers of phishing attacks that can lead to the installation of infostealers and malware, compromising user data and security.

3

What products or software are affected by the FileFix attack?

The attack specifically targets users of ESET antivirus and internet security software.

4

What type of malware is associated with the FileFix attack?

The FileFix attack is primarily associated with the StealC infostealer and malware downloader.

5

How does the FileFix attack operate to deceive victims?

It masquerades as a legitimate Facebook security alert to trick users into executing malicious files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203