메뉴
BL
Ars Technica • 14일 전

클릭픽스(CklickFix) 공격, PC·맥 감염으로 확산 중

IMP
8/10
핵심 요약

가짜 CAPTCHA(캡차)를 통해 사용자가 악성 명령어를 직접 터미널에 붙여넣게 유도하는 'ClickFix' 공격이 주류 기법으로 자리 잡았습니다. 해킹된 합법 웹사이트를 통해 유포되며 크렘린 지원 해킹그룹도 이 기법을 활용하고 있고, 맥의 Gatekeeper 보호도 우회 가능해 사용자 교육과 방어 대책 마련이 시급합니다.

번역된 본문

얼마 전까지만 해도 ClickFix 공격은 생소한 기법이었다. 이제는 PC와 맥 사용자 모두를 감염시키는 단순하고 효과적인 방법으로 공격자들 사이에서 주류가 되었다. 필요한 것은 해킹된 웹사이트(그리 어려운 작업이 아니다), 가짜 CAPTCHA 오버레이, 단 한 줄의 터미널 명령어뿐이다. 너무나 많은 방문자가 그 명령어를 복사해 붙여넣고 실행하는 바람에 거의 모든 악성코드 유포자들이 이 기법을 채택했다. 심지어 크렘린 지원 해킹 그룹들도 합류하고 있다.

독립 연구자 케빈 보먼트(Kevin Beaumont)는 목요일에 "레딧(Reddit)이 ClickFix로 컴퓨터가 감염됐다는 글로 도배되고 있다. 곳곳의 정상 웹사이트들이 가짜 캡차 프롬프트를 띄우도록 해킹당하고 있다"고 지적했다.

몇몇은 상황을 악화시킨다

이 사이트를 읽는 상당수를 포함해 경험이 많은 인터넷 사용자들은 이 공격을 쉽게 무시한다. 이들은 보통 사기에 당한 사람들을 탓하며 그들의 순진함과 부주의를 비웃는다. 하지만 현실은 그렇지 않다. 일반 사용자들에게 컴퓨터와 인터넷 사용은 너무나 어려워졌다. 닫을 수 없는 전면 광고, 끝없이 이어지는 그림 캡차, 원하는 기능을 숨겨버리는 끊임없이 바뀌는 인터페이스 등을 겪으면서 그들은 터무니없고 번거로워 보이는 지시에 둔감해졌다. ClickFix 공격자들은 이런 피로감을 이용하고 있다.

일반적으로 공격은 간단한 CAPTCHA 이미지로 시작되며, Cloudflare의 것처럼 위장하는 경우가 많다. 확인란을 클릭하면 사용자는 악성 명령어를 감추는 방식으로 가려진 한 줄의 텍스트를 보게 된다. 그리고 그 텍스트를 복사해 Windows 실행창, PowerShell 또는 macOS 터미널에 붙여넣고 엔터를 치라는 지시를 받는다. 이 지시는 사람들이 수년간 사용해온 웹사이트에서 나온다. 그 안내는 지난 10년간 강요받아온 일들과 별다르게 의심스럽지 않아 보인다. 컴퓨터 보안에 대한 확실한 이해가 없는 사람이 왜 망설이겠는가?

공격자들에게 ClickFix는 일을 훨씬 쉽게 만들어준다. ClickFix 이전에는 보안업체 BlueVoyant가 'Lorem Ipsum'으로 추적한 이 악성코드를 유포하기 위해 SEO 조작 및 악성 광고가 달린 다운로드 포털, 마이크로소프트가 신뢰하는 코드 서명 인증서, 지속적으로 순환하는 도메인을 통한 MSI 설치 패키지 배포 등 자원을 많이 소모하는 인프라가 필요했다.

BlueVoyant는 "2026년 5월 말 ClickFix로 전환하면서 코드 서명 요구사항이 완전히 사라졌다. 유효하게 서명된 설치 프로그램의 정당성 대신, 사용자가 자발적으로 자신의 터미널에서 악성 명령어를 실행한다는 또 다른 형태의 정당성으로 대체된 것"이라고 말했다. 또 "ClickFix 모델은 피해자 pool을 마이크로소프트 팀즈를 검색하는 사용자에서 손상된 웹사이트를 방문하는 모든 사람으로 확대한다"고 덧붙였다.

macOS 사용자라고 사정이 나은 것은 아니다. 맥 보안업체 Jamf와 한 연구자는 Gatekeeper 보호를 우회할 수 있는 macOS용 ClickFix 변종을 문서화했다. ClickFix 공격자들은 계속 새로운 방법으로 공공 서비스를 악용하고 있다. Cisco Talos에 따르면 공개된 구글 시트(Google Sheets) 문서도 활용된다. 러시아 국가 후원 그룹 Sandworm을 포함한 다른 공격자들은 블록체인 기반 스마트 컨트랙트에 명령제어(C2) 인프라를 호스팅하고 있다. 보안업체 Netskope는 최근 같은 접근 방식을 사용한 또 다른 캠페인을 발견했다. 이 회사는 해당 캠페인에 신호를 보내는 5,400개 사이트를 확인했으며, 이는 캠페인의 도달 범위와 규모를 보여준다.

그리고 OS 제조사와 방어자들이 새로운 방어책을 구축할 때마다 공격자들은 문서화된 우회 방법을 계속 찾아내고 있다.

이 모든 것의 결론은 ClickFix가 각종 악성코드를 유포하는 매우 효과적이고 효율적인 수단이라는 점이다. 이 기법은 사라지지 않을 것이며, 피해자를 비난하거나 창피를 주는 것은 문제를 악화시킬 뿐이다. 상당수의 플러그인과 독립형 도구들이…

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav It wasn’t that long ago that ClickFix attacks were exotic. Now the technique has become mainstream as attackers reap its simplicity and effectiveness in infecting users of PCs and Macs alike. All that’s required is a compromised website—a painless enough task—a fake CAPTCHA overlay, and the inclusion of a single terminal command. So many visitors get suckered into pasting and running the command that just about every malware pusher has adopted the technique. Even Kremlin-backed hacking groups are joining in. “Reddit is becoming post after post after post of people getting their computer infected via ClickFix,” independent researcher Kevin Beaumont observed Thursday . “Legit websites everywhere [are] getting hacked to serve the fake captcha prompts.” How many of us make things worse More seasoned Internet users—a fair number who read this site—are quick to dismiss the attack. They typically blame the people who fall for the scams and marvel at their gullibility and lack of attention. The reality is that for more casual users, using computers and the Internet has become so difficult—think impossible-to-close interstitials, CAPTCHAs with an endless series of pictures to analyze, and constantly changing interfaces that bury the features they’re looking for—that they have grown desensitized to instructions that seem ridiculous and burdensome. ClickFix attackers are capitalizing on this fatigue. Typically, attacks begin with a simple CAPTCHA image, often masquerading as one from Cloudflare. After engaging with the box, the user sees a line of text, often obscured in a way to mask any malicious commands. Then the user is instructed to copy the text and paste it into the Windows Run, PowerShell, or macOS terminal and click Enter. The instructions come from websites people have used for years. The directions seem no more suspicious than things they’ve been required to do for a decade. Why would someone without a firm grasp of computer security have any reason to hesitate? For the people behind the attacks, ClickFix now makes their job much easier. Prior to ClickFix, they would have needed to install the malware (tracked as Lorem Ipsum, security firm BlueVoyant said recently) using resource-intensive infrastructure, including SEO-manipulated and malvertised download portals, Microsoft-trusted signing certificates, and continuously rotated domains for delivering Microsoft Installer packages. “The pivot to ClickFix in late May 2026 eliminates the code-signing requirement entirely, substituting the legitimacy of a validly signed installer with a different form of legitimacy: a user voluntarily executing the malicious command in their own terminal,” BlueVoyant said. “[T]he ClickFix model broadens the victim pool from users searching specifically for Microsoft Teams to anyone browsing a compromised website.” The situation for macOS users isn’t any better. Both Mac security firm Jamf and a researcher have ​​documented macOS variations of ClickFix that can bypass Gatekeeper protections. ClickFix attackers keep finding new ways to use public services—including publicly published Google Sheets documents, according to Cisco Talos. Other attackers, including Russia’s state-sponsored Sandworm, are hosting their control infrastructure in blockchain-based smart contracts. Security firm Netskope recently found another campaign that used the same approach. The security company counted 5,400 sites beaconing to it, an indication of the reach and scope of that campaign. And as OS makers and defenders build new defenses, attackers keep finding documented ways to work around them. The upshot of all this is that ClickFix is a highly effective and efficient means of spreading all sorts of malware. It’s not going away, and victim-blaming or shaming only makes the problem worse. There are a fair number of plugins, standalone products, and built-in defenses that are designed to blunt the success of ClickFix attacks. For instance, BlockBlock, the software that monitors Macs for processes that seek to permanently install themselves, can block ClickFix attacks as soon as a user presses the ⌘+V keys. Ublock has been updated to do something similar. Beyond those fixes, those of us with more security training should build awareness with our less experienced neighbors, family members, and friends. The mass adoption of ClickFix demonstrates its success, and it’s not going away any time soon. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 77 Comments