Security agencies and researchers warned that ClickFix social-engineering attacks are spreading through fake verification and brand-impersonation pages that mimic services such as Google reCAPTCHA and Cloudflare, then trick users into opening Win+R or Terminal and pasting clipboard-loaded commands. Recent campaigns have used poisoned websites, fake search results, and spoofed update pages to push victims into launching malicious PowerShell, mshta, WebDAV, or shell-based payloads, turning trusted brands and verification flows into an initial access vector without directly compromising the impersonated organizations.
The activity has delivered a wide range of malware, including ACR Stealer, HijackLoader, StealC, Remus, Amatera Stealer, CastleLoader, NetSupport, Rust-based stealers, and a DPRK-linked macOS backdoor tied to Contagious Interview. Microsoft said ACR Stealer campaigns targeting enterprise users stole browser credentials, cookies, tokens, and business files, used scheduled tasks and process injection for persistence and evasion, and in some cases relied on EtherHiding to resolve command-and-control infrastructure from Ethereum smart contracts; the macOS campaign similarly used clipboard-driven execution, LaunchAgent persistence, and follow-on payloads that targeted browser data, developer and cloud keys, and cryptocurrency wallets. Defenders were urged to block command execution from untrusted prompts, hunt for published indicators of compromise, and educate users that legitimate verification pages do not require running commands locally.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Microsoft said ACR Stealer campaigns targeted enterprise users between late April and mid-June 2026 using ClickFix lures and delivery chains involving WebDAV with rundll32.exe or MSHTA with a PowerShell downloader. The malware stole credentials, cookies, tokens, and business files, while using persistence and evasion techniques.
Blackpoint Security reported a ClickFix-style attack in which a user was tricked into running a malicious PowerShell command that fetched a second-stage script, suppressed AMSI and PowerShell telemetry, established COM hijack persistence, and loaded an Overlord RAT variant called SpaceX1337 directly into memory. Its SOC isolated the affected host, found no lateral movement, and reverse engineered the loader, persistence mechanism, and payload.
A new macOS malvertising campaign using a fake full-screen update page and ClickFix clipboard instructions was attributed to a DPRK-linked threat actor tied to the Contagious Interview cluster, also known as UNC5342. The campaign delivered a Node.js backdoor using EtherHiding and follow-on payloads including a crypto-focused information stealer and a malicious Chrome extension.
Microsoft published mitigations and indicators of compromise for the rising ACR Stealer activity and assessed the malware as a malware-as-a-service offering likely repackaging Amatera Stealer. It also noted some variants used EtherHiding through blockchain-based dead-drop resolvers.
The CERT Azerbaijan notice said Opera introduced a browser feature called Paste Protect to help block clipboard-based malicious command execution associated with ClickFix attacks. This was presented as a defensive response to the technique.
CERT Azerbaijan issued a warning about increasing ClickFix social-engineering attacks that impersonate services such as Google reCAPTCHA and Cloudflare and trick users into running malicious commands. The notice said these campaigns can deliver malware including HijackLoader, StealC, Remus, Amatera Stealer, CastleLoader, NetSupport, and Rust-based stealers.
A campaign poisoned more than 700 websites, including Harvard, Oxford, and DuckDuckGo sites, and used a fake Cloudflare page to trick visitors into executing a ClickFix infection chain. The article cites this as an example of brand impersonation being used for initial access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcecysecurity.news
Open sourceblackpointcyber.com
Open sourcecert.gov.az
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.