InstallFix is a ClickFix-style social-engineering malware-delivery technique that abuses cloned software-installation documentation and counterfeit installation pages. Victims are induced to copy and execute attacker-supplied terminal, shell, or Windows Run-dialog commands rather than install legitimate software. Campaigns have used malvertising and software-themed lures, including developer-tool and AI coding-assistant installation guides, to direct users to convincingly replicated documentation containing altered one-line installer commands.
On Windows, observed InstallFix execution chains use mshta and PowerShell to retrieve and execute staged code. A disguised polyglot carrier can establish persistence through a scheduled task, launch 32-bit PowerShell, and attempt to disable the Antimalware Scan Interface before subsequent payload execution. InstallFix has been used as a delivery route for Amatera Stealer, including in-memory loading intended to reduce detection by file-based controls. InstallFix-style campaigns have targeted Windows and macOS users, exploiting the widespread practice of pasting installation commands from web pages into local shells.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
A disguised MP3/HTA file can create a scheduled task, launch 32-bit PowerShell and disable the Antimalware Scan Interface before subsequent code runs.
It’s a variant of the ClickFix technique that presents a fake installation page (often a convincing clone of official documentation) and tricks the user into copying and running a malicious command.
Windows visitors can receive a separate InstallFix route that uses mshta and PowerShell. A disguised MP3/HTA file can create a scheduled task, launch 32-bit PowerShell and disable the Antimalware Scan Interface.
The subsequent stages used arithmetic fog, opaque predicates, and shellcode to inject the Amatera Stealer PE directly into memory.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows staging and execution chain using a disguised MP3/HTA payload, scheduled-task persistence, mshta, and 32-bit PowerShell. It disables AMSI before running subsequent payloads.
Windows ClickFix delivery component masquerading as an MP3/HTA file. It establishes persistence via a scheduled task, runs 32-bit PowerShell, and disables AMSI before executing later-stage code.
Windows ClickFix loader delivered as an MP3/HTA polyglot. It creates scheduled-task persistence, invokes 32-bit PowerShell, disables AMSI, and prepares later in-memory payload delivery.
A Windows ClickFix loader delivered as an MP3/HTA polyglot. It establishes scheduled-task persistence, runs PowerShell, attempts to disable AMSI, derives victim-specific infrastructure, and leads to in-memory payload loading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.