Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 4 IP / 2311 hostnames
ClickFix is a social-engineering malware delivery technique and mature Malware-as-a-Service ecosystem that tricks victims into manually executing attacker-supplied commands on their own systems.
Profile source: Mallory opens in a new tabClickFix
ClickFix is a social-engineering malware delivery technique and mature Malware-as-a-Service ecosystem that tricks victims into manually executing attacker-supplied commands on their own systems. It commonly presents fake CAPTCHA checks, Cloudflare verification pages, browser or operating system update prompts, meeting errors, SSL warnings, or job-interview themed lures. The lure page typically uses JavaScript to place a malicious command into the victim’s clipboard, then instructs the user to paste and run it in Windows Run, Windows Terminal, or macOS Terminal. Rather than relying on software exploitation, ClickFix abuses trusted user actions and legitimate system tools to initiate compromise.
ClickFix campaigns are used to deliver a wide range of payloads, especially infostealers and remote access trojans. Frequently reported payloads include Lumma Stealer, DarkGate, XWorm, AsyncRAT, NetSupport, SectopRAT, CastleLoader-delivered RATs, and other post-exploitation implants. Observed infection chains often execute largely in memory and abuse signed or native binaries such as PowerShell, mshta, curl, rundll32, finger, tar, cmd, and other living-off-the-land tools to reduce detection. Some campaigns also use DLL sideloading, shellcode loaders, Python runtimes, Tor-routed communications, blockchain-based configuration retrieval, and API-driven backends that generate unique obfuscated commands per victim.
The ecosystem has industrialized since first emerging in 2024. Underground ClickFix kits have been sold with prebuilt lure templates, payload integration, domain rotation, malvertising support, and operator support channels. Researchers have documented multi-operator backend infrastructure, antivirus-evasion claims, and delivery workflows tailored by operating system and language. Related variants and adjacent tradecraft include CrashFix, FileFix, PromptFix, ConsentFix, and ClickFake Interview.
Delivery has been observed through compromised websites used as watering holes, poisoned WordPress and Ghost CMS sites, phishing and fake job-interview workflows, malvertising, SEO poisoning, and fake software or browser update pages. Threat actors ranging from commodity cybercriminals to state-linked groups have incorporated ClickFix into operations. Public reporting has linked ClickFix-style campaigns to APT28, MuddyWater, Kimsuky, and North Korean Contagious Interview activity, while financially motivated actors have used it to broaden initial access and malware deployment.
ClickFix targets both Windows and macOS users. On Windows, campaigns commonly lead to credential theft, session theft, persistence, reconnaissance, lateral movement, and broader post-exploitation through RAT payloads. On macOS, ClickFix-style delivery has been used to deploy infostealers that harvest validated login passwords, browser credentials, cookies, crypto-wallet data, Keychain contents, and password-manager material, sometimes using coercive forced-interaction techniques to obtain user secrets. ClickFix is best understood not as a single malware family but as a scalable operator-driven delivery framework for initial access and follow-on malware execution.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac b4a3205341b7d6eee7d8a810300a39960ac66c7fb89f585a06c6e1e921a49820 07f53dbaccf650bf676c1352c6887edf10f3e8e790c8367b892c06a062ca1950 Reported operators
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.
Recent Contagious Interview campaigns, also referred to as ClickFake Interview, involve a social engineering technique known as ClickFix. A targeted job seeker receives an invitation to participate in a job application process... instructed to copy and paste command lines... to download and execute a supposed update... unknowingly deploying malware in the process.
Recent Contagious Interview campaigns, also referred to as ClickFake Interview, involve a social engineering technique known as ClickFix. A targeted job seeker receives an invitation to participate in a job application process... instructed to copy and paste command lines... to download and execute a supposed update... unknowingly deploying malware in the process.
"...a new ClickFix variant we have dubbed 'CrashFix' that intentionally crashes the browser then baits users into running malicious commands..."
"...use of ClickFix to deliver the TINYWHALE downloader..."
First tracked in early 2026, the operation uses a technique called ClickFix to manipulate victims into running malicious commands on their own machines — making them the unwitting delivery mechanism for the attack.
Exploited software
MITRE ATT&CK
Reporting
ClickFix est désormais un Malware-as-a-Service (MaaS) mature
The front end is ClickFix. Group-IB assesses that with high confidence and has never seen it.
ClickFix has moved from a one-off social engineering trick into an industrialized attack ecosystem... Behind the campaign diversity and payload variety is a structured Malware-as-a-Service (MaaS) economy that has industrialized the production, distribution, and operation of ClickFix.
In mid-July 2026, researchers discovered a sophisticated ClickFix campaign operating on a subdomain belonging to the popular digital asset platform, Artlist.
Threat actors compromised legitimate WordPress websites to inject ClickFix JavaScript that delivers malware to unsuspecting visitors. Rather than hardcoding command-and-control infrastructure, the script dynamically retrieves its configuration from a Polygon blockchain smart contract...
ClickFix has evolved from a clever, socially engineered attack vector into an entire industrialized malware ecosystem that is outpacing traditional security defenses... ClickFix is a social engineering technique that tricks users into manually executing malicious code on their own computers.
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake "prove you're human" pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise.
Prenons l'exemple de l'épidémie de malwares ClickFix qui prolifère sur des milliers de sites compromis. Ces sites affichent une fausse boîte de dialogue Cloudflare ou CAPTCHA qui incite les visiteurs à copier-coller une commande, infectant ainsi leur système à leur insu.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.