CLickFix Compromises Websites of over 100 US Auto Dealerships

May 14, 2025

INCIDENT

Websites of over 100 auto dealerships were found serving malicious ClickFix code in a supply chain compromise. A threat actor infected LES Automotive, a shared video service unique to dealerships. Websites using the video service would serve a ClickFix webpage to their visitors. The attack was using the fake reCAPTCHA variation of ClickFix, relying on PowerShell commands to deploy payloads on the victim’s machine, and ultimately infect them with the remote access trojan.

Incident Date

March 17, 2025

Estimated Cost


No cost values disclosed.

Type of Malware

Threat Source

No threat source identified