Skip to content
Malware family macOSWindows

ClickFix

ClickFix is a social-engineering malware delivery technique and mature Malware-as-a-Service ecosystem that tricks victims into manually executing attacker-supplied commands on their own systems.

Profile source: Mallory opens in a new tab

ClickFix

Family profile

ClickFix is a social-engineering malware delivery technique and mature Malware-as-a-Service ecosystem that tricks victims into manually executing attacker-supplied commands on their own systems. It commonly presents fake CAPTCHA checks, Cloudflare verification pages, browser or operating system update prompts, meeting errors, SSL warnings, or job-interview themed lures. The lure page typically uses JavaScript to place a malicious command into the victim’s clipboard, then instructs the user to paste and run it in Windows Run, Windows Terminal, or macOS Terminal. Rather than relying on software exploitation, ClickFix abuses trusted user actions and legitimate system tools to initiate compromise.

ClickFix campaigns are used to deliver a wide range of payloads, especially infostealers and remote access trojans. Frequently reported payloads include Lumma Stealer, DarkGate, XWorm, AsyncRAT, NetSupport, SectopRAT, CastleLoader-delivered RATs, and other post-exploitation implants. Observed infection chains often execute largely in memory and abuse signed or native binaries such as PowerShell, mshta, curl, rundll32, finger, tar, cmd, and other living-off-the-land tools to reduce detection. Some campaigns also use DLL sideloading, shellcode loaders, Python runtimes, Tor-routed communications, blockchain-based configuration retrieval, and API-driven backends that generate unique obfuscated commands per victim.

The ecosystem has industrialized since first emerging in 2024. Underground ClickFix kits have been sold with prebuilt lure templates, payload integration, domain rotation, malvertising support, and operator support channels. Researchers have documented multi-operator backend infrastructure, antivirus-evasion claims, and delivery workflows tailored by operating system and language. Related variants and adjacent tradecraft include CrashFix, FileFix, PromptFix, ConsentFix, and ClickFake Interview.

Delivery has been observed through compromised websites used as watering holes, poisoned WordPress and Ghost CMS sites, phishing and fake job-interview workflows, malvertising, SEO poisoning, and fake software or browser update pages. Threat actors ranging from commodity cybercriminals to state-linked groups have incorporated ClickFix into operations. Public reporting has linked ClickFix-style campaigns to APT28, MuddyWater, Kimsuky, and North Korean Contagious Interview activity, while financially motivated actors have used it to broaden initial access and malware deployment.

ClickFix targets both Windows and macOS users. On Windows, campaigns commonly lead to credential theft, session theft, persistence, reconnaissance, lateral movement, and broader post-exploitation through RAT payloads. On macOS, ClickFix-style delivery has been used to deploy infostealers that harvest validated login passwords, browser credentials, cookies, crypto-wallet data, Keychain contents, and password-manager material, sometimes using coercive forced-interaction techniques to obtain user secrets. ClickFix is best understood not as a single malware family but as a scalable operator-driven delivery framework for initial access and follow-on malware execution.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
4 IP / 2311 hostnames

Leading locations

  • US1243
  • DE151
  • FR139
  • BR78
  • IN75
  • IT51
  • SG48
  • ES46
  • GB45
  • NL29
  • ID26
  • VN23

Leading providers

  • Cloudflare, Inc.268
  • Hostinger International Limited216
  • Cloudflare London, LLC184
  • Oracle Corporation145
  • Namecheap, Inc.122
  • OVH SAS90

Infrastructure traits

  • Hosting 2218
  • Anycast 741
  • Proxy 190
  • Vpn 30
  • Residential Proxy 3
  • Mobile 1

Samples

Recent associated samples

Reported operators

Threat actors

8 named in public reporting
Kimsuky

ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.

APT28

ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.

MuddyWater

ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.

Lazarus

Recent Contagious Interview campaigns, also referred to as ClickFake Interview, involve a social engineering technique known as ClickFix. A targeted job seeker receives an invitation to participate in a job application process... instructed to copy and paste command lines... to download and execute a supposed update... unknowingly deploying malware in the process.

Contagious Interview

Recent Contagious Interview campaigns, also referred to as ClickFake Interview, involve a social engineering technique known as ClickFix. A targeted job seeker receives an invitation to participate in a job application process... instructed to copy and paste command lines... to download and execute a supposed update... unknowingly deploying malware in the process.

KongTuke

"...a new ClickFix variant we have dubbed 'CrashFix' that intentionally crashes the browser then baits users into running malicious commands..."

UNC4221

"...use of ClickFix to deliver the TINYWHALE downloader..."

APT38

First tracked in early 2026, the operation uses a technique called ClickFix to manipulate victims into running malicious commands on their own machines — making them the unwitting delivery mechanism for the attack.

Exploited software

Vulnerabilities linked to ClickFix

1 CVEs

MITRE ATT&CK

ClickFix in ATT&CK

36 distinct techniques

Reporting

Research mentioning ClickFix

Jul 18
Cyberveille

ClickFix : une méthodologie d'attaque industrialisée invisible aux EDR et antivirus | CyberVeille

ClickFix est désormais un Malware-as-a-Service (MaaS) mature

Jul 16
The Hacker News

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

The front end is ClickFix. Group-IB assesses that with high confidence and has never seen it.

Jul 15
Help Net Security

ClickFix is changing the economics of social engineering - Help Net Security

ClickFix has moved from a one-off social engineering trick into an industrialized attack ecosystem... Behind the campaign diversity and payload variety is a structured Malware-as-a-Service (MaaS) economy that has industrialized the production, distribution, and operation of ClickFix.

Jul 14
Malware News

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist - Malware Analysis - Malware Analysis, News and Indicators

In mid-July 2026, researchers discovered a sophisticated ClickFix campaign operating on a subdomain belonging to the popular digital asset platform, Artlist.

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

Threat actors compromised legitimate WordPress websites to inject ClickFix JavaScript that delivers malware to unsuspecting visitors. Rather than hardcoding command-and-control infrastructure, the script dynamically retrieves its configuration from a Polygon blockchain smart contract...

Jul 14
Dark Reading

ClickFix's Mushrooming Ecosystem Demands New Defense Tactics

ClickFix has evolved from a clever, socially engineered attack vector into an entire industrialized malware ecosystem that is outpacing traditional security defenses... ClickFix is a social engineering technique that tricks users into manually executing malicious code on their own computers.

Jul 1
The Hacker News

Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery

ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.

Jun 26
Zdnet

Chrome 150 va désactiver votre bloqueur de pub, et c'est un vrai ...

Prenons l'exemple de l'épidémie de malwares ClickFix qui prolifère sur des milliers de sites compromis. Ces sites affichent une fausse boîte de dialogue Cloudflare ou CAPTCHA qui incite les visiteurs à copier-coller une commande, infectant ainsi leur système à leur insu.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.