LES Automotive
Incident posture
Linked entities
- Victim
- LES Automotive
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
Attackers compromised the video service provider LES Automotive, which is used by more than one hundred auto dealership websites, and injected malicious JavaScript that redirected visitors to a ClickFix page posing as a reCAPTCHA. The page copied a PowerShell command to the clipboard and instructed users to paste and run it, ultimately downloading and executing SectopRAT. The infection chain involved obfuscated script calls to external hosts, a ZIP payload hosted via a URL shortener, and the execution of an extracted executable that deployed the remote access trojan. Security analysis confirmed the presence of SectopRAT in sandboxed samples, indicating successful compromise of dealership visitors' machines.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The incident began when the third‑party video service provider LES Automotive was compromised, allowing threat actors to inject malicious JavaScript into the file les_video_srp.js hosted at https://www.idostream[.]com/member/les_video_srp.js. This script, when loaded by a dealership website, dynamically created a script element that fetched content from security-confirmation.help/captchav2, which in turn redirected visitors to a ClickFix page at deliveryoka.com/webservice_ionic/captchav2.html?us. The ClickFix page presented a fake reCAPTCHA checkbox labeled “I’m not a robot” and, after the user clicked it, displayed instructions to open the Windows Run dialog, paste clipboard contents, and execute them. Embedded in the JavaScript was a Russian comment translating to “Clear the previous timeout,” indicating the actors’ language background.
When users followed the on‑screen instructions, the clipboard contained a Base64‑encoded PowerShell command that, when executed, downloaded a payload from bitly.cx/UnluS, which redirected to main-login.sbs/maison/tree. This stage fetched a second Bitly link, bitly.cx/2CoZ2, which resolved to main-login.sbs/fernandino/brend, a file saved as Lancaster.zip and extracted to the temporary folder. The extracted executable, zkwindow.exe, was then launched, leading to the installation of the SectopRAT remote access trojan as confirmed by sandbox analysis that awarded the sample a perfect threat score. Indicators of compromise included the domains security-confirmation[.]help, deliveryoka[.]com, bitly[.]cx, and main-login[.]sbs, along with the specific file hash for Lancaster.zip. Over one hundred automobile dealerships that integrated the LES Automotive video service were exposed to this supply chain attack, with the malicious file captchav2.html having been present on the compromised host since at least April 2024, as evidenced by its last‑modified timestamp. The attack was observed in early March 2025, following an October 2024 Health and Human Services warning about Russian‑speaking cybercriminals employing ClickFix tactics since April 2024. LES Automotive subsequently remediated the compromised service, ending the injection of the malicious JavaScript.
Sources
Sources available to members: 2 sources.