A new wave of social engineering attacks, known as ClickFix and its variant JackFix, is leveraging highly convincing fake Windows Update screens to trick users into executing malicious commands on their systems. Attackers lure victims—often through malvertising or fake adult websites—onto pages that mimic legitimate Windows update prompts, instructing them to open the Windows Run dialog and paste a command copied to their clipboard. This command initiates a multi-stage infection chain, typically resulting in the deployment of infostealer malware such as Lumma or Rhadamanthys. The campaigns employ advanced evasion techniques, including the use of mshta.exe, obfuscated scripts, and steganography to hide malicious payloads within PNG images, all executed in-memory to avoid detection by endpoint security solutions.
The JackFix variant intensifies the psychological manipulation by combining anxiety-inducing phishing lures with full-screen browser hijacks, making the fake update appear urgent and legitimate. Reports indicate a significant increase in JackFix-related incidents, with hundreds of submissions to VirusTotal, particularly in the US and Europe. Technical analysis reveals that these attacks are evolving to bypass existing ClickFix mitigations, using new delivery chains and contextually relevant lures. The campaigns are believed to be operated by Russian-speaking threat actors, as evidenced by developer comments found in some attack infrastructure. Organizations are advised to educate users about these sophisticated lures and implement technical controls to block the execution of suspicious commands and scripts.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Researchers found Russian-language comments in the lure code and other overlaps suggesting the operators were likely Russian-speaking cybercriminals. Reports also noted infrastructure overlap with other stealer-delivery campaigns and broad activity concentrated in the US and Europe.
Researchers documented a new ClickFix variant dubbed JackFix that used fake pornography sites, malvertising, and fake Windows blue-screen or update prompts to increase psychological pressure on victims. The variant was designed to bypass existing ClickFix mitigations and improve infection success.
Technical analysis revealed that the new campaign concealed malware inside PNG image pixel data and used mshta and obfuscated PowerShell to decrypt and load a .NET loader. Final payloads included infostealers such as LummaC2 and Rhadamanthys, with code injection into trusted processes like explorer.exe.
By November 2025, researchers identified a new ClickFix campaign that used convincing full-screen fake Windows Update pages to trick users into pasting and running malicious commands through the Windows Run dialog. The campaign targeted Windows users and corporate employees and relied heavily on user interaction.
Huntress reported that ClickFix-related incidents increased by 313% over the previous six months, indicating significant growth in the technique's use during 2025. The increase provided context for the later emergence of more advanced lures and delivery methods.
As of 2025-11-19, fake Windows Update sites used in the campaign were still online, although the malware payloads were no longer being hosted there. This showed that parts of the campaign infrastructure remained available even after some content had been removed.
In May 2025, NCC Group reported a ClickFix-style attack in which victims were tricked via a fake CAPTCHA into executing malicious commands that led to LummaC2 infection. This established an earlier related variant before the later fake Windows Update wave.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcehelpnetsecurity.com
Open sourcedarkreading.com
Open sourcemalwarebytes.com
Open sourcethehackernews.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.