{"id":10507,"date":"2025-07-14T12:38:57","date_gmt":"2025-07-14T05:38:57","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=10507"},"modified":"2026-02-05T12:39:04","modified_gmt":"2026-02-05T05:39:04","slug":"chieu-thuc-clickfix-giup-tin-tac-chiem-quyen-kiem-soat-may-tinh-chi-bang-mot-cu-dan-lenh","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/2025\/07\/14\/chieu-thuc-clickfix-giup-tin-tac-chiem-quyen-kiem-soat-may-tinh-chi-bang-mot-cu-dan-lenh\/","title":{"rendered":"Chi\u00eau th\u1ee9c \u201cClickFix\u201d gi\u00fap tin t\u1eb7c chi\u1ebfm quy\u1ec1n ki\u1ec3m so\u00e1t m\u00e1y t\u00ednh ch\u1ec9 b\u1eb1ng m\u1ed9t c\u00fa d\u00e1n l\u1ec7nh"},"content":{"rendered":"<p><b>ClickFix &#8211; th\u1ee7 \u0111o\u1ea1n l\u1eeba \u0111\u1ea3o d\u1ef1 ki\u1ebfn s\u1ebd b\u00f9ng n\u1ed5 trong c\u00e1c chi\u1ebfn d\u1ecbch t\u1ea5n c\u00f4ng m\u1ea1ng trong 2025. Kh\u00e1c v\u1edbi c\u00e1c h\u00ecnh th\u1ee9c t\u1ea5n c\u00f4ng truy\u1ec1n th\u1ed1ng qua email l\u1eeba \u0111\u1ea3o hay file \u0111\u00ednh k\u00e8m \u0111\u1ed9c h\u1ea1i, chi\u00eau th\u1ee9c n\u00e0y l\u1ee3i d\u1ee5ng t\u00e2m l\u00fd mu\u1ed1n &#8220;s\u1eeda nhanh l\u1ed7i m\u00e1y&#8221; \u0111\u1ec3 d\u1ee5 ng\u01b0\u1eddi d\u00f9ng t\u1ef1 tay ch\u1ea1y l\u1ec7nh \u0111\u1ed9c h\u1ea1i. <\/b><\/p>\n<div style=\"text-align: center\"><a class=\"js-lbImage\" style=\"cursor: pointer\" href=\"https:\/\/whitehat.vn\/attachments\/1752477958423-png.17303\/\" target=\"_blank\" rel=\"noopener\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-fancybox=\"lb-thread-18558\" data-caption=\"&lt;h4&gt;1752477958423.png&lt;\/h4&gt;&lt;p&gt;&lt;a href=&quot;https:&amp;#x2F;&amp;#x2F;whitehat.vn&amp;#x2F;threads&amp;#x2F;chieu-thuc-clickfix-giup-tin-tac-chiem-quyen-kiem-soat-may-tinh-chi-bang-mot-cu-dan-lenh.18558&amp;#x2F;#post-44065&quot; class=&quot;js-lightboxCloser&quot;&gt;WhiteHat Team \u00b7 14&amp;#x2F;07&amp;#x2F;2025 l\u00fac 2:36 PM&lt;\/a&gt;&lt;\/p&gt;\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage \" title=\"1752477958423.png\" src=\"https:\/\/whitehat.vn\/data\/attachments\/17\/17638-572f8eff2d8efe1213880e6cb10a1345.jpg\" alt=\"1752477958423.png\" width=\"854\" height=\"400\" \/><\/a>\u200b<\/div>\n<p>ClickFix l\u00e0 m\u1ed9t chi\u00eau th\u1ee9c t\u1ea5n c\u00f4ng x\u00e3 h\u1ed9i (social engineering), trong \u0111\u00f3 k\u1ebb x\u1ea5u gi\u1ea3 danh k\u1ef9 thu\u1eadt vi\u00ean ho\u1eb7c c\u00e1c th\u01b0\u01a1ng hi\u1ec7u c\u00f4ng ngh\u1ec7 l\u1edbn nh\u01b0 DocuSign, Okta, cung c\u1ea5p \u201ch\u01b0\u1edbng d\u1eabn s\u1eeda l\u1ed7i\u201d cho c\u00e1c s\u1ef1 c\u1ed1 ph\u1ed5 bi\u1ebfn nh\u01b0 l\u1ed7i driver, pop-up phi\u1ec1n ph\u1ee9c hay l\u1ed7i \u0111\u0103ng nh\u1eadp. H\u1eadu qu\u1ea3 l\u00e0 tin t\u1eb7c c\u00f3 th\u1ec3 chi\u1ebfm quy\u1ec1n ki\u1ec3m so\u00e1t m\u00e1y t\u00ednh, \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u, th\u1eadm ch\u00ed m\u1edf \u0111\u01b0\u1eddng cho t\u1ea5n c\u00f4ng ransomware.<\/p>\n<p>Nh\u01b0ng thay v\u00ec s\u1eeda l\u1ed7i th\u1eadt, h\u01b0\u1edbng d\u1eabn n\u00e0y y\u00eau c\u1ea7u ng\u01b0\u1eddi d\u00f9ng copy-d\u00e1n m\u1ed9t \u0111o\u1ea1n l\u1ec7nh (th\u01b0\u1eddng l\u00e0 PowerShell) v\u00e0o khung Run (Win+R) ho\u1eb7c c\u1eeda s\u1ed5 terminal (Win+X) tr\u00ean Windows. \u0110o\u1ea1n l\u1ec7nh n\u00e0y \u0111\u01b0\u1ee3c ch\u00e8n s\u1eb5n v\u00e0o clipboard (b\u1ed9 nh\u1edb t\u1ea1m) th\u00f4ng qua m\u00e3 JavaScript \u0111\u1ed9c h\u1ea1i t\u1eeb c\u00e1c trang web gi\u1ea3, qu\u1ea3ng c\u00e1o \u0111\u1ed9c h\u1ea1i, video h\u01b0\u1edbng d\u1eabn gi\u1ea3 m\u1ea1o ho\u1eb7c di\u1ec5n \u0111\u00e0n h\u1ed7 tr\u1ee3 k\u1ef9 thu\u1eadt \u201cr\u1edfm\u201d \u2013 m\u1ed9t k\u1ef9 thu\u1eadt c\u00f2n \u0111\u01b0\u1ee3c g\u1ecdi l\u00e0 pastejacking.<\/p>\n<p>Nguy hi\u1ec3m n\u1eb1m \u1edf ch\u1ed7 kh\u00f4ng c\u00f3 file \u0111\u00ednh k\u00e8m \u0111\u1ed9c h\u1ea1i, kh\u00f4ng c\u00f3 link l\u1eeba \u0111\u1ea3o v\u00e0 ch\u00ednh ng\u01b0\u1eddi d\u00f9ng l\u00e0 ng\u01b0\u1eddi ch\u1ee7 \u0111\u1ed9ng ch\u1ea1y m\u00e3 \u0111\u1ed9c m\u00e0 kh\u00f4ng h\u1ec1 hay bi\u1ebft.<\/p>\n<p>Trong n\u0103m 2025, c\u00e1c nh\u00f3m t\u1ea5n c\u00f4ng \u0111\u00e3 k\u1ebft h\u1ee3p ClickFix v\u00e0o nhi\u1ec1u chi\u1ebfn d\u1ecbch ph\u00e1t t\u00e1n ph\u1ea7n m\u1ec1m gi\u00e1n \u0111i\u1ec7p v\u00e0 m\u00e3 \u0111\u1ed9c chi\u1ebfm quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n t\u1eeb xa, bao g\u1ed3m:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">NetSupport RAT: L\u1ee3i d\u1ee5ng giao di\u1ec7n DocuSign v\u00e0 Okta gi\u1ea3 m\u1ea1o, d\u1ee5 ng\u01b0\u1eddi d\u00f9ng d\u00e1n l\u1ec7nh PowerShell. K\u1ecbch b\u1ea3n n\u00e0y t\u1eebng t\u1ea5n c\u00f4ng v\u00e0o c\u00e1c ng\u00e0nh y t\u1ebf, ph\u00e1p l\u00fd, vi\u1ec5n th\u00f4ng v\u00e0 khai kho\u00e1ng v\u00e0o th\u00e1ng 5\/2025.<\/li>\n<li data-xf-list-type=\"ul\">Latrodectus Malware: Ph\u00e1t t\u00e1n qua c\u00e1c website b\u1ecb c\u00e0i m\u00e3 ClearFake, l\u1ee3i d\u1ee5ng DLL side-loading \u0111\u1ec3 c\u00e0i m\u00e3 \u0111\u1ed9c.<\/li>\n<li data-xf-list-type=\"ul\">Lumma Stealer: Nh\u1eafm v\u00e0o l\u0129nh v\u1ef1c IT, \u00f4 t\u00f4, n\u0103ng l\u01b0\u1ee3ng\u2026 v\u1edbi c\u00e1c l\u1ec7nh MSHTA \u0111\u1ed9c h\u1ea1i v\u00e0 t\u00ean mi\u1ec1n gi\u1ea3 m\u1ea1o d\u1ecbch v\u1ee5 ghi log IP.<\/li>\n<\/ul>\n<p>T\u00e1c \u0111\u1ed9ng c\u1ee7a ClickFix r\u1ea5t nguy hi\u1ec3m v\u00e0 kh\u00f3 ph\u00e1t hi\u1ec7n:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Ng\u01b0\u1eddi d\u00f9ng b\u1ecb chi\u1ebfm quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n m\u00e1y t\u00ednh (qua Remote Access Trojan).<\/li>\n<li data-xf-list-type=\"ul\">D\u1eef li\u1ec7u v\u00e0 t\u00e0i kho\u1ea3n b\u1ecb \u0111\u00e1nh c\u1eafp, bao g\u1ed3m email, m\u1eadt kh\u1ea9u, t\u00e0i li\u1ec7u n\u1ed9i b\u1ed9.<\/li>\n<li data-xf-list-type=\"ul\">M\u1edf \u0111\u01b0\u1eddng cho ransomware ho\u1eb7c m\u00e3 \u0111\u1ed9c kh\u00e1c l\u00e2y lan.<\/li>\n<li data-xf-list-type=\"ul\">C\u00e1c ng\u00e0nh b\u1ecb \u1ea3nh h\u01b0\u1edfng tr\u1ea3i r\u1ed9ng: c\u00f4ng ngh\u1ec7 cao, ng\u00e2n h\u00e0ng, s\u1ea3n xu\u1ea5t, b\u00e1n l\u1ebb, ch\u00ednh ph\u1ee7, ti\u1ec7n \u00edch c\u00f4ng c\u1ed9ng\u2026<\/li>\n<\/ul>\n<p>Chi\u00eau th\u1ee9c n\u00e0y c\u0169ng g\u00e2y kh\u00f3 kh\u0103n l\u1edbn cho c\u00e1c h\u1ec7 th\u1ed1ng b\u1ea3o m\u1eadt truy\u1ec1n th\u1ed1ng b\u1edfi v\u00ec:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Kh\u00f4ng c\u00f3 file l\u1ea1 t\u1ea3i xu\u1ed1ng ban \u0111\u1ea7u.<\/li>\n<li data-xf-list-type=\"ul\">Kh\u00f4ng c\u00f3 link email l\u1eeba \u0111\u1ea3o.<\/li>\n<li data-xf-list-type=\"ul\">H\u00e0nh \u0111\u1ed9ng ch\u1ea1y m\u00e3 l\u00e0 do ch\u00ednh ng\u01b0\u1eddi d\u00f9ng th\u1ef1c hi\u1ec7n.<\/li>\n<\/ul>\n<p>Tuy nhi\u00ean, c\u00e1c d\u1ea5u v\u1ebft forensics v\u1eabn c\u00f3 th\u1ec3 ph\u00e1t hi\u1ec7n, nh\u01b0 c\u00e1c l\u1ec7nh b\u1ea5t th\u01b0\u1eddng trong Windows RunMRU ho\u1eb7c phi\u00ean PowerShell \u0111\u01b0\u1ee3c kh\u1edfi ch\u1ea1y sau clipboard paste.<\/p>\n<p>Ng\u01b0\u1eddi d\u00f9ng ph\u1ed5 th\u00f4ng ch\u00ednh l\u00e0 m\u1ee5c ti\u00eau c\u1ee7a ClickFix, do \u0111\u00f3 n\u00e2ng cao nh\u1eadn th\u1ee9c l\u00e0 \u01b0u ti\u00ean h\u00e0ng \u0111\u1ea7u. Nh\u1eefng d\u1ea5u hi\u1ec7u c\u1ea7n c\u1ea3nh gi\u00e1c:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">Trang web y\u00eau c\u1ea7u \u201cd\u00e1n l\u1ec7nh \u0111\u1ec3 s\u1eeda l\u1ed7i\u201d.<\/li>\n<li data-xf-list-type=\"ul\">H\u01b0\u1edbng d\u1eabn k\u1ef9 thu\u1eadt l\u1ea1 tr\u00ean video\/di\u1ec5n \u0111\u00e0n kh\u00f4ng ch\u00ednh th\u1ed1ng.<\/li>\n<li data-xf-list-type=\"ul\">C\u1ea3nh b\u00e1o t\u1eeb Windows y\u00eau c\u1ea7u quy\u1ec1n qu\u1ea3n tr\u1ecb sau khi d\u00e1n l\u1ec7nh.<\/li>\n<\/ul>\n<p>\u0110\u1ec3 gi\u1ea3m thi\u1ec3u nguy c\u01a1 b\u1ecb t\u1ea5n c\u00f4ng qua k\u1ef9 thu\u1eadt ClickFix, WhiteHat khuy\u1ebfn c\u00e1o c\u00e1c t\u1ed5 ch\u1ee9c v\u00e0 ng\u01b0\u1eddi d\u00f9ng n\u00ean th\u1ef1c hi\u1ec7n c\u00e1c bi\u1ec7n ph\u00e1p sau:<\/p>\n<ol>\n<li data-xf-list-type=\"ol\">Lu\u00f4n c\u1eadp nh\u1eadt ph\u1ea7n m\u1ec1m v\u00e0 h\u1ec7 \u0111i\u1ec1u h\u00e0nh<br \/>\nC\u00e0i \u0111\u1eb7t \u0111\u1ea7y \u0111\u1ee7 c\u00e1c b\u1ea3n v\u00e1 b\u1ea3o m\u1eadt \u0111\u1ec3 b\u1ecbt k\u00edn c\u00e1c l\u1ed7 h\u1ed5ng \u0111\u00e3 bi\u1ebft m\u00e0 hacker c\u00f3 th\u1ec3 l\u1ee3i d\u1ee5ng.<\/li>\n<li data-xf-list-type=\"ol\">D\u00f9ng ph\u1ea7n m\u1ec1m b\u1ea3o m\u1eadt \u0111\u00e1ng tin c\u1eady<br \/>\nTri\u1ec3n khai ph\u1ea7n m\u1ec1m di\u1ec7t virus, t\u01b0\u1eddng l\u1eeda v\u00e0 c\u00e1c c\u00f4ng c\u1ee5 b\u1ea3o v\u1ec7 \u0111\u1ea7u cu\u1ed1i \u0111\u1ec3 ph\u00e1t hi\u1ec7n v\u00e0 ng\u0103n ch\u1eb7n m\u00e3 \u0111\u1ed9c.<\/li>\n<li data-xf-list-type=\"ol\">Tuy\u1ec7t \u0111\u1ed1i c\u1ea3nh gi\u00e1c v\u1edbi l\u1ec7nh \u201cd\u00e1n v\u00e0 ch\u1ea1y\u201d t\u1eeb ngu\u1ed3n l\u1ea1<br \/>\nKh\u00f4ng l\u00e0m theo b\u1ea5t k\u1ef3 h\u01b0\u1edbng d\u1eabn n\u00e0o y\u00eau c\u1ea7u copy-paste l\u1ec7nh v\u00e0o Run (Win+R) ho\u1eb7c PowerShell\/Terminal (Win+X) d\u00f9 nh\u00ecn c\u00f3 v\u1ebb h\u1ee3p l\u00fd hay c\u00e1c l\u1ec7nh \u0111\u00f3 \u0111\u1ebfn t\u1eeb th\u01b0\u01a1ng hi\u1ec7u quen thu\u1ed9c.<\/li>\n<li data-xf-list-type=\"ol\">\u0110\u00e0o t\u1ea1o nh\u1eadn th\u1ee9c an ninh cho nh\u00e2n vi\u00ean<br \/>\nT\u1ed5 ch\u1ee9c c\u00e1c kh\u00f3a hu\u1ea5n luy\u1ec7n \u0111\u1ecbnh k\u1ef3 gi\u00fap ng\u01b0\u1eddi d\u00f9ng nh\u1eadn di\u1ec7n chi\u00eau tr\u00f2 ClickFix v\u00e0 c\u00e1c h\u00ecnh th\u1ee9c l\u1eeba \u0111\u1ea3o tinh vi kh\u00e1c.<\/li>\n<li data-xf-list-type=\"ol\">Gi\u00e1m s\u00e1t h\u00e0nh vi h\u1ec7 th\u1ed1ng b\u1ea5t th\u01b0\u1eddng\n<ul>\n<li data-xf-list-type=\"ul\">Theo d\u00f5i clipboard \u0111\u1ec3 ph\u00e1t hi\u1ec7n c\u00e1c \u0111o\u1ea1n l\u1ec7nh \u0111\u1ed9c b\u1ecb d\u00e1n l\u00e9n.<\/li>\n<li data-xf-list-type=\"ul\">Ghi nh\u1eadn v\u00e0 ph\u00e2n t\u00edch c\u00e1c phi\u00ean PowerShell b\u1ea5t th\u01b0\u1eddng.<\/li>\n<li data-xf-list-type=\"ul\">Ki\u1ec3m tra m\u1ee5c RunMRU trong registry Windows \u2013 n\u01a1i l\u01b0u l\u1ea1i c\u00e1c l\u1ec7nh \u0111\u00e3 ch\u1ea1y qua c\u1eeda s\u1ed5 Run.<\/li>\n<\/ul>\n<\/li>\n<li data-xf-list-type=\"ol\">S\u1eed d\u1ee5ng c\u00e1c c\u00f4ng c\u1ee5 b\u1ea3o m\u1eadt n\u00e2ng cao\n<ul>\n<li data-xf-list-type=\"ul\">Palo Alto Networks: Advanced WildFire, URL Filtering, DNS Security.<\/li>\n<li data-xf-list-type=\"ul\">Cortex XDR: Gi\u00e1m s\u00e1t h\u00e0nh vi v\u00e0 ph\u1ea3n \u1ee9ng t\u1ef1 \u0111\u1ed9ng v\u1edbi c\u00e1c ho\u1ea1t \u0111\u1ed9ng kh\u1ea3 nghi.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>ClickFix l\u00e0 v\u00ed d\u1ee5 \u0111i\u1ec3n h\u00ecnh cho th\u1ea5y k\u1ebb t\u1ea5n c\u00f4ng kh\u00f4ng c\u1ea7n c\u00f4ng c\u1ee5 k\u1ef9 thu\u1eadt cao, ch\u1ec9 c\u1ea7n t\u00e2m l\u00fd ng\u01b0\u1eddi d\u00f9ng nh\u1eb9 d\u1ea1 v\u00e0 thi\u1ebfu c\u1ea3nh gi\u00e1c. Trong b\u1ed1i c\u1ea3nh k\u1ef9 thu\u1eadt t\u1ea5n c\u00f4ng ng\u00e0y c\u00e0ng tinh vi v\u00e0 \u201cth\u00e2n thi\u1ec7n\u201d, c\u00e1c t\u1ed5 ch\u1ee9c v\u00e0 ng\u01b0\u1eddi d\u00f9ng c\u00e1 nh\u00e2n kh\u00f4ng th\u1ec3 ch\u1ec9 tr\u00f4ng ch\u1edd v\u00e0o ph\u1ea7n m\u1ec1m di\u1ec7t virus. Gi\u1ea3i ph\u00e1p n\u1eb1m \u1edf s\u1ef1 c\u1ea3nh gi\u00e1c, gi\u00e1o d\u1ee5c an ninh m\u1ea1ng c\u01a1 b\u1ea3n v\u00e0 m\u1ed9t h\u1ec7 th\u1ed1ng gi\u00e1m s\u00e1t th\u00f4ng minh.<\/p>\n<div style=\"text-align: right\"><b><i>Theo WhiteHat, Cyber Press<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/chieu-thuc-clickfix-giup-tin-tac-chiem-quyen-kiem-soat-may-tinh-chi-bang-mot-cu-dan-lenh.18558\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/chieu-thuc-clickfix-giup-tin-tac-chiem-quyen-kiem-soat-may-tinh-chi-bang-mot-cu-dan-lenh.18558\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>ClickFix &#8211; th\u1ee7 \u0111o\u1ea1n l\u1eeba \u0111\u1ea3o d\u1ef1 ki\u1ebfn s\u1ebd b\u00f9ng n\u1ed5 trong c\u00e1c chi\u1ebfn d\u1ecbch t\u1ea5n c\u00f4ng m\u1ea1ng trong 2025. Kh\u00e1c v\u1edbi c\u00e1c h\u00ecnh th\u1ee9c t\u1ea5n c\u00f4ng truy\u1ec1n th\u1ed1ng qua email l\u1eeba \u0111\u1ea3o hay file \u0111\u00ednh k\u00e8m \u0111\u1ed9c h\u1ea1i, chi\u00eau th\u1ee9c n\u00e0y l\u1ee3i d\u1ee5ng t\u00e2m l\u00fd mu\u1ed1n &#8220;s\u1eeda nhanh l\u1ed7i m\u00e1y&#8221; \u0111\u1ec3 d\u1ee5 ng\u01b0\u1eddi d\u00f9ng [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-10507","post","type-post","status-publish","format-standard","hentry","category-tin-tuc-cua-vien"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10507","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=10507"}],"version-history":[{"count":0,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10507\/revisions"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=10507"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=10507"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=10507"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}