A new social engineering campaign, dubbed "ClickFix," is targeting users with deceptive "Word Online" error messages to distribute the DarkGate remote access trojan. The attack begins when a user visits a compromised or malicious website that displays a fake notification about a missing browser extension. Victims are prompted to click a "How to fix" button, which uses JavaScript to copy a malicious PowerShell command to their clipboard. Users are then instructed to open a PowerShell terminal and paste the command, unknowingly initiating the infection chain. This method leverages user interaction to bypass traditional browser-based security controls and evade automated detection systems.
Once executed, the PowerShell script downloads a malicious HTA file from a remote server, which acts as a staging ground for the final payload. The infection process involves multiple layers of obfuscation, including base64-encoded data and reverse functions embedded within the HTML structure. The final stage deploys DarkGate, a potent remote access trojan capable of full system compromise. Researchers from Point Wild's Lat61 Threat Intelligence Team have highlighted the sophistication of this campaign, noting its reliance on user trust in familiar troubleshooting procedures to facilitate malware installation.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Point Wild's Lat61 Threat Intelligence Team identified a social-engineering campaign using fake 'Word Online' or browser-fix messages to trick users into copying and executing a malicious PowerShell command that installs DarkGate. The researchers documented a multi-stage infection chain involving an HTA file, AutoIt components, obfuscated scripts, and DES-decrypted payloads that provide remote access and persistence.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.