ClickFix

Malware

A ClickFix attack relies on malicious code on a webpage to display a prompt to the user, asking them to fix an error or perform a reCAPTCHA challenge, to prove they are human. When the user clicks on the prompt, a malicious command is copied to the clipboard, and the user is also instructed to perform keyboard combinations that open the Windows Run prompt, paste the copied command into the prompt, and execute it.

The social engineering technique has been used for a couple of years, but started gaining popularity among cybercriminals and APTs last year

ClickFix attacks have been adopted by a wide range of threat actors: Interlock and other ransomware gangs and North Korean hackers.

Threat Actors Known to use this Malware

No threat actors identified