LES Automotive
Incident posture
Linked entities
- Victim
- LES Automotive
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
Over 100 auto dealerships were compromised after attackers infiltrated the shared video service LES Automotive and injected malicious JavaScript into its les_video_srp.js file. The script served a ClickFix page that prompted visitors to execute a PowerShell command, which downloaded a ZIP file containing the SectopRAT loader zkwindow.exe. Execution of the loader led to the deployment of the remote access trojan on victims’ machines. The attack relied on obfuscated code and dynamic injection, with some users receiving a benign version of the script. Associated indicators include the domains security‑confirmation.help, deliveryoka.com, bitly.cx, main‑login.sbs and the file hash 1a34c9b4500cf7859c36c102209902202fb7188aca1ba759f2d5018bf2655cc1 for Lancaster.zip.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The compromise began when threat actors infiltrated LES Automotive, a third‑party video service used by many auto dealerships, and inserted malicious JavaScript into the file les_video_srp.js hosted at https://www.idostream[.]com/member/les_video_srp.js. This script, when loaded by a dealership site, dynamically created another script element that pointed to https://security-confirmation.help/captchav2, which in turn redirected visitors to a ClickFix page at https://www.deliveryoka.com/webservice_ionic/captchav2.html?us. The ClickFix page contained a comment in Russian reading “Очистите предыдущий таймаут” (“Clear the previous timeout”) and was designed to place a specific PowerShell command into the user’s clipboard after they clicked a checkbox labeled “I’m not a robot.” Because the injection was performed dynamically, most urlscan captures showed only the benign version of the script, while a minority revealed the malicious payload.
When a visitor followed the on‑screen instructions, the clipboard content—a base64‑encoded PowerShell string—was pasted into the Windows Run prompt and executed. The decoded command downloaded a file from https://bitly.cx/UnluS, which redirected to https://main-login.sbs/maison/tree. That response instructed the system to retrieve another file from https://bitly.cx/2CoZ2, save it as Lancaster.zip in the temporary folder, extract the archive, and run the executable zkwindow.exe located in the extracted version_21 folder. Execution of zkwindow.exe installed the SectopRAT remote access trojan on the victim’s machine. Sandbox analysis of the Lancaster.zip file with Triage resulted in a perfect threat score, confirming the presence of SectopRAT. The malicious captchav2.html file had been present on the compromised host since at least April 2024, indicating a prolonged window of exposure.
The campaign affected the websites of over one hundred auto dealerships that relied on the LES Automotive video service, exposing their visitors to the ClickFix social engineering chain and the subsequent SectopRAT infection. According to the source reports, LES Automotive has since remediated the issue, removing the malicious JavaScript from les_video_srp.js and restoring the legitimate version of the service. No further details about specific remediation steps or post‑incident monitoring were provided in the available material. The incident concluded with the removal of the malicious payload from the third‑party service, ending the active distribution of the ClickFix‑delivered SectopRAT to dealership visitors.
Sources
Sources available to members: 2 sources.