Mexico City C5 Warns of 'ClickFix' Scam Using Fake Alerts to Install Malware
Translated from Spanish, summarized and contextualized by DistantNews.
At a glance
- Mexico City's C5 has issued a warning about a new fraud tactic called "ClickFix."
- Cybercriminals use fake websites and false security alerts to trick users into running malicious commands.
- This tactic can lead to malware installation, allowing attackers to control devices and steal data.
The Center for Command, Control, Computing, Communications, and Citizen Contact (C5) in Mexico City has alerted the public to a new cyber fraud scheme known as "ClickFix." This tactic employs fake websites and deceptive security alerts to manipulate users into executing malicious commands on their devices.
Cybercriminals are reportedly exploiting users by instructing them to copy and paste commands into system tools like PowerShell, Windows Terminal, or the Run window. They falsely claim these actions are necessary to resolve supposed security issues. However, executing these commands can install malware, granting attackers unauthorized access to personal data and sensitive information, and potentially taking full control of the victim's computer.
The C5 highlighted that these attacks pose a significant challenge due to the increasingly sophisticated techniques used to gain access to devices and personal information. To combat this threat, the center advises users to avoid suspicious websites, keep their systems updated, and secure their accounts with strong passwords.
Furthermore, the C5 strongly recommends against executing commands requested from web pages, downloading files from unknown sources, or entering personal data on untrustworthy sites. If a user has already copied or executed a command, the immediate advice is to disconnect the affected device from the internet, change passwords from a secure alternative device, perform a comprehensive antivirus scan, and seek specialized technical support.
The attacks represent a challenge due to the use of more sophisticated techniques to access devices and personal data.
Originally published by El Universal in Spanish. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.