CSIDB logo
Incident

LES Automotive

Incident posture

Attack window
Nov 2025
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-08-13 01:53

Linked entities

Victim
LES Automotive
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Apr 2024
Discovered
Undetermined
Disclosed
Mar 2025
Resolved
Mar 2025

Summary

Attackers compromised the video service provider LES Automotive, which is used by more than one hundred auto dealership websites, and injected malicious JavaScript that redirected visitors to a ClickFix page posing as a reCAPTCHA. The page copied a PowerShell command to the clipboard and instructed users to paste and run it, ultimately downloading and executing SectopRAT. The infection chain involved obfuscated script calls to external hosts, a ZIP payload hosted via a URL shortener, and the execution of an extracted executable that deployed the remote access trojan. Security analysis confirmed the presence of SectopRAT in sandboxed samples, indicating successful compromise of dealership visitors' machines.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The incident began when the third‑party video service provider LES Automotive was compromised, allowing threat actors to inject malicious JavaScript into the file les_video_srp.js hosted at https://www.idostream[.]com/member/les_video_srp.js. This script, when loaded by a dealership website, dynamically created a script element that fetched content from security-confirmation.help/captchav2, which in turn redirected visitors to a ClickFix page at deliveryoka.com/webservice_ionic/captchav2.html?us. The ClickFix page presented a fake reCAPTCHA checkbox labeled “I’m not a robot” and, after the user clicked it, displayed instructions to open the Windows Run dialog, paste clipboard contents, and execute them. Embedded in the JavaScript was a Russian comment translating to “Clear the previous timeout,” indicating the actors’ language background.

When users followed the on‑screen instructions, the clipboard contained a Base64‑encoded PowerShell command that, when executed, downloaded a payload from bitly.cx/UnluS, which redirected to main-login.sbs/maison/tree. This stage fetched a second Bitly link, bitly.cx/2CoZ2, which resolved to main-login.sbs/fernandino/brend, a file saved as Lancaster.zip and extracted to the temporary folder. The extracted executable, zkwindow.exe, was then launched, leading to the installation of the SectopRAT remote access trojan as confirmed by sandbox analysis that awarded the sample a perfect threat score. Indicators of compromise included the domains security-confirmation[.]help, deliveryoka[.]com, bitly[.]cx, and main-login[.]sbs, along with the specific file hash for Lancaster.zip. Over one hundred automobile dealerships that integrated the LES Automotive video service were exposed to this supply chain attack, with the malicious file captchav2.html having been present on the compromised host since at least April 2024, as evidenced by its last‑modified timestamp. The attack was observed in early March 2025, following an October 2024 Health and Human Services warning about Russian‑speaking cybercriminals employing ClickFix tactics since April 2024. LES Automotive subsequently remediated the compromised service, ending the injection of the malicious JavaScript.

Sources

Sources available to members: 2 sources.

CSIDB