InstallFix is a malware delivery technique/campaign identified as a variant of ClickFix. It uses fake software installation pages—often convincing clones of legitimate documentation—to trick users into copying and executing malicious one-line install commands. Reporting cited here states that InstallFix emerged as the top malware threat in March 2026, accounting for 14.3% of incidents, and that ClickFix-style delivery accounted for 43.7% of malware delivery in Q1 2026. In observed activity, attackers used AI/developer tooling as lures, including cloned Anthropic Claude Code installation instructions, and drove victims to the fake pages via malvertising and sponsored search results for queries such as "Claude Code install" and "Claude Code CLI." The campaign targeted both Windows and macOS users. On execution, the altered command fetched attacker-hosted payloads rather than legitimate installers; researchers observed execution beginning with cmd.exe and spawning mshta.exe to retrieve and run additional scripts from a malicious domain, enabling staged payload delivery and persistence. One reported payload matched Amatera Stealer, an infostealer that steals browser-stored credentials, session cookies, authentication tokens, and other system information. Attackers were also observed hosting cloned installation pages on legitimate platforms including Cloudflare Pages, Squarespace, and Tencent EdgeOne to blend into normal traffic and reduce takedown likelihood. High-confidence behavioral indicators from the reporting include cloned install pages, modified curl | bash-style commands, malicious domains replacing official vendor download locations, and suspicious process chains involving cmd.exe followed by mshta.exe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware delivery variant tied to ClickFix-style social engineering. It uses fake software installation pages, including cloned AI tool documentation, to trick users into copying and executing malicious commands themselves.
A malware distribution campaign that uses cloned software installation pages and malicious one-line install commands (e.g., curl-to-bash) to trick users into executing an infostealer payload on Windows and macOS.
Malware/campaign name associated with weaponized (malvertised) software installation guides used to trick users into installing malicious payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.