New FileFix attack runs JScript while bypassing Windows MoTW alerts

New FileFix Attack Uses JScript to Bypass Windows MoTW Protection
Photo: BleepingComputer

New FileFix Attack Uses JScript to Bypass Windows MoTW Protection

A new cyberattack technique, dubbed ‘FileFix’, has been discovered to bypass the Mark of the Web (MoTW) protection in Windows by executing malicious scripts when users save HTML files. The attack works by exploiting how browsers handle saved webpages and is more subtle than previous attacks. It involves social engineering, tricking victims into saving a webpage as an .HTA file, which automatically runs a malicious JScript via mshta.exe when opened. The key vulnerability lies in how HTML files saved as ‘Webpage, Complete’ do not receive the MoTW tag, thus bypassing important security warnings. To defend against this, experts suggest disabling mshta.exe, enabling file extension visibility, and blocking HTML attachments in emails. The attack has been detailed by security researcher mr.d0x, who previously revealed other variants like the ‘ClickFix’ attack. This new variant, although requiring some interaction, can still deceive less knowledgeable users if the malicious webpage appears legitimate, such as offering MFA backup codes.

Leave a Reply

Your email address will not be published. Required fields are marked *