Cybercriminals leverage ClickFix scams and hidden malware in image files to spread banking trojans and remote access tools.
Security researchers have uncovered a sophisticated attack campaign where criminals are using deceptive download prompts and hidden malware within image files to infect computers with dangerous remote access tools. The operation, tracked by threat analysts, demonstrates how attackers are getting more creative in bypassing traditional security defenses that most people rely on.
The attackers are employing a two-stage approach: first, they trick users into clicking what appears to be a legitimate download button (a technique called ClickFix), then they hide malicious code within PNG image files—a format most people think is completely safe. Once downloaded, these files unleash banking trojans and remote access tools that give criminals complete control over infected systems.
Think of this attack like a disguised package delivery. On the surface, everything looks normal—you're downloading what you think is a simple image. But inside that innocent-looking file is dangerous software waiting to take over your computer. The criminals are betting that people will trust image files because they seem harmless compared to executable programs.
The ClickFix component works by displaying urgent-looking pop-up messages that mimic official warnings from Microsoft, Apple, or other trusted companies. These fake alerts pressure users into clicking download buttons, believing they need to install security updates or fix critical problems. In reality, they're installing malware.
This threat matters because it targets everyday people, not just large corporations. Anyone browsing the internet could encounter one of these fake prompts. The malware's purpose—remote access tools—means criminals can:
Additionally, security experts revealed that hosting platform cPanel had a serious vulnerability affecting website owners. A flaw allowed users with basic account permissions to execute commands with administrative-level access, essentially bypassing security layers designed to keep accounts separate. While cPanel has patched this issue, the incident highlights how attackers constantly search for overlooked security gaps.
You can significantly reduce your risk by following these straightforward steps:
Website administrators using cPanel should ensure they've installed the latest security updates addressing the privilege escalation vulnerability. The hosting company has provided a targeted release addressing multiple access control issues, so updating should be a priority.
This campaign demonstrates that staying safe online requires constant vigilance and healthy skepticism toward unexpected prompts and downloads.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters →