The TA585 threat group has orchestrated a sophisticated cybercrime operation leveraging the MonsterV2 Malware-as-a-Service (MaaS) platform and advanced social engineering techniques, notably the ClickFix method. TA585 distinguishes itself by controlling the entire attack chain, from infrastructure hosting to phishing campaign execution and malware deployment, without relying on external brokers. Their primary payload, MonsterV2, is a subscription-based, multi-functional malware capable of data theft and system takeover, and is distributed through highly targeted phishing campaigns. The group employs advanced filtering and anti-bot systems to ensure only genuine victims are targeted, and has also been observed distributing other infostealers such as Lumma Stealer and Rhadamanthys.
ClickFix attacks, which have rapidly become one of the most prevalent social engineering threats in 2025, exploit user trust by convincing victims to copy and paste malicious commands into their own systems, bypassing traditional security awareness training. These attacks are often disguised as verification steps, CAPTCHA checks, or even social media tutorials, and have been observed spreading through trusted platforms, including GitHub. A new variant, FileFix, further refines this approach by leveraging Windows File Explorer for stealthier execution. Security researchers have noted a dramatic increase in ClickFix-style attacks, with detections rising over 500% in six months and HTML/FakeCaptcha (ClickFix) ranking among the top malware detections in early 2025.

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
TA585 also reportedly used fake GitHub issue notifications that appeared to be security warnings and tagged users to draw attention. The notifications redirected targets to attacker-controlled ClickFix pages as part of the infection chain.
In 2025, TA585 was described as operating an end-to-end campaign using ClickFix lures on compromised sites and phishing pages to trick victims into running PowerShell commands. Those commands downloaded follow-on scripts designed to bypass defenses and install MonsterV2.
ClickFix kits became commercialized on dark web forums, lowering the barrier to entry for attackers. This commercialization helped broaden use of the technique across a wider range of threat actors.
By late 2025, FileFix had been observed in campaigns delivering malware including Interlock RAT and the StealC infostealer. This showed the newer copy-paste technique was already being operationalized for real malware delivery.
Multiple notable campaigns used ClickFix-style social engineering in 2025, including PhantomCaptcha linked to Star Blizzard and TikTok-themed scams distributing Aura Stealer. These operations relied on fake verification or troubleshooting prompts to trick users into pasting malicious commands.
ClickFix campaigns expanded rapidly in 2025, with reported growth of more than 500% over six months. The technique was used against organizations in sectors including technology, finance, government, and energy, and was adopted by both cybercriminal and nation-state actors.
FileFix, an evolution of ClickFix that abuses the Windows File Explorer address bar to execute malicious code, was first revealed. The technique was described as stealthier than standard ClickFix because it can avoid some normal security prompts and alerts.
MonsterV2, a subscription-based malware-as-a-service platform with data theft and remote takeover capabilities, was first advertised in underground forums. It later became a primary payload associated with TA585 ClickFix campaigns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.