ClickFix is a social-engineering-driven activity cluster centered on tricking users into manually executing malicious PowerShell commands copied to the clipboard from fake browser update, certificate, or error dialogs. The cluster emerged in 2024 on compromised websites and is characterized by deceptive prompts instructing victims to open an elevated PowerShell console and paste attacker-supplied code, shifting execution to user action and reducing reliance on conventional file-based initial payload delivery. Observed ClickFix infection chains used compromised sites and iframe-based content to present fraudulent browser error messages. The pasted PowerShell typically downloaded and launched follow-on payloads, including information-stealing malware such as Vidar Stealer. Reporting also identified overlap between ClickFix-style delivery and later malware distribution associated with the Golden Chickens ecosystem, including a lure delivered through a shortcut file that executed a payload via mshta.exe in a manner consistent with previously observed ClickFix tradecraft. The cluster’s tradecraft emphasizes social engineering, clipboard-based command delivery, PowerShell execution, and use of trusted Windows utilities to stage malware. Related campaigns in the broader ecosystem using the same copy-paste execution pattern have delivered loaders, remote access tools, stealers, and cryptocurrency-mining payloads. High-confidence attribution of ClickFix to a specific nation state or formally tracked threat actor is not currently established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an activity cluster whose tradecraft overlaps with at least one TerraStealerV2 distribution LNK sample (MP4-masquerading payload executed via mshta.exe).
Activity cluster observed on compromised sites using iframe-based fake browser update/error overlays that instruct victims to paste malicious PowerShell, ultimately leading to Vidar Stealer before the payload infrastructure was taken offline.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.