Cybercriminals are increasingly leveraging sophisticated social engineering tactics that exploit users' trust in Microsoft branding and their tendency to follow technical instructions. Microsoft has reported a significant rise in ClickFix attacks, a method where attackers trick users into executing malicious code by presenting fake error messages or technical problems that appear to require immediate user intervention. These attacks are designed to bypass traditional phishing protections, as they rely on manipulating human behavior rather than exploiting technical vulnerabilities. According to Microsoft’s latest Digital Defense Report, ClickFix was observed as the initial access method in 47% of attacks, highlighting its widespread adoption among threat actors. The report also notes a broader trend of AI abuse, extortion, and ransomware, but emphasizes the unique danger posed by ClickFix due to its adaptability and reliance on social engineering. In parallel, security researchers at Cofense have identified a new tech support scam that uses Microsoft’s logo and branding to create a convincing illusion of a browser lock, further manipulating victims into believing their systems are compromised. This scam typically begins with a phishing email offering a fake refund, luring users to click a link that leads to a CAPTCHA challenge, which both increases the attack’s credibility and helps evade automated security tools. Once the victim completes the CAPTCHA, they are confronted with pop-ups mimicking genuine Microsoft security alerts, and their browser is manipulated to appear locked, even disabling mouse control to heighten the sense of urgency and panic. The attackers then prompt the victim to call a fake support number, where further social engineering is used to steal sensitive information or gain deeper access to the victim’s system. Both attack types demonstrate a shift in cybercriminal tactics toward exploiting human psychology and trusted brands, rather than relying solely on technical exploits. Microsoft’s data-driven insights underscore the scale of the problem, with the company processing over 100 trillion signals daily and blocking millions of malware and phishing attempts. The sophistication of these attacks makes user awareness and behavioral change critical, as traditional security tools may not detect or prevent such threats. Organizations are urged to educate users about these evolving tactics, emphasizing the risks of following unsolicited technical instructions or responding to suspicious support requests. The convergence of ClickFix and tech support scams signals a broader trend in cybercrime, where attackers blend technical manipulation with psychological pressure to achieve their objectives. As these methods continue to evolve, both individuals and enterprises must remain vigilant and adapt their defenses accordingly. The use of Microsoft branding in these scams amplifies their effectiveness, making it essential for users to verify the legitimacy of any technical prompts or support communications. Security teams should update training materials and incident response protocols to address these emerging threats, ensuring rapid detection and mitigation. The ongoing rise of such social engineering attacks highlights the need for a multi-layered security approach that combines technical controls with robust user education.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Subsequent coverage described ClickFix as an attack that effectively tricks victims into 'hacking themselves' by manually executing malicious commands. The reporting focused on how to recognize the scam pattern and avoid being manipulated into running attacker-supplied code.
Researchers reported a tech-support scam that uses Microsoft branding and a fake browser-lock screen to pressure victims into believing their system is compromised. The scam is designed to steal data by convincing users to follow attacker-controlled instructions under the guise of Microsoft support.
Microsoft publicly warned that ClickFix is being used by both cybercriminal and nation-state actors to deliver malware including ransomware, infostealers, and remote access trojans. The company emphasized that user awareness and behavior change are the primary defenses because standard anti-phishing controls are often ineffective against this tactic.
Microsoft observed a major increase in the use of the ClickFix tactic, reporting that it accounted for 47% of initial access methods seen by Microsoft Defender Experts. The technique tricks users into copying and pasting malicious commands from fake error messages or phishing lures, enabling fileless malware execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourcezdnet.com
Open sourcezdnet.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.