Fraud Management & Cybercrime , Social Engineering Users Download Malware in Bid to Placate Meta Pooja Tikekar ( @PoojaTikekar) • September 18, 2025 Attacker pressures the victim to paste a malicious command into the address bar of an upload window. (Image: Acronis/ISMG) A newly surfaced FileFix social engineering campaign puts a new spin on ClickFix attacks by goading users into loading malware under the guise of reporting a wrongful account suspension to social media giant Facebook. See Also: Live Webinar | AI-Powered Defense Against AI-Driven Threats ClickFix attacks have surged over the last year as a technique for manipulating users into executing malicious code by offering supposed steps to fixing a technical problem. A hacker going by “mr. d0x” in June demonstrated a stealthier version that shifts the focus of the social engineering prompt away from the Windows Run dialog window to the more familiar Windows File Explorer. Researchers from backup and recovery firm Acronis said Tuesday they discovered “a rare in-the-wild example” of a FileFix campaign. “The adversary behind this attack demonstrated significant investment in tradecraft,” making it more sophisticated than ClickFix attacks. Victims likely get sucked into the scam by following a link from a phishing
Read More
FileFix Campaign Uses Facebook Suspension as Bait

FileFix Campaign Uses Facebook Suspension as Bait