JackFix is a variant of the ClickFix attack that combines aggressive social engineering with technical evasion to bypass existing defenses. It uses anxiety-inducing phishing and malvertising lures, including fake pornography sites and a convincing fake Windows blue screen or screen lock, to pressure victims into executing malicious commands. The fake blue screen can lock the victim’s screen and block certain keyboard shortcuts, increasing the likelihood of user compliance. Technically, JackFix encodes malicious scripts and commands in arrays and reconstructs them at runtime to evade detection, and it uses content-based URL filtering to deliver malware only to intended victims while redirecting others to benign sites, complicating analysis and infrastructure flagging. The delivered payload is described as a large, heavily obfuscated PowerShell script that seeks administrative privileges, disables Microsoft Defender protections by adding exclusions, and downloads multiple commercial malware families in a spray-and-pray fashion, including Rhadamanthys, Vidar 2.0, RedLine, and Amadey, as well as loaders. Reporting cited in the content attributes JackFix activity to suspected Russian-speaking cybercriminals. Hundreds of JackFix-related submissions have reportedly appeared on VirusTotal, with most observed activity in the US and Europe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JackFix is a new variant of the ClickFix attack that leverages both social engineering and technical evasion to bypass security defenses. It represents an evolution in attack techniques, making it more difficult for traditional security measures to detect and block.
JackFix is a sophisticated social engineering and phishing attack variant that leverages psychological manipulation, fake Windows blue screens, and technical evasion techniques to trick users into running malicious commands. It circumvents traditional ClickFix mitigations and delivers multiple malware payloads via obfuscated PowerShell scripts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.