Threat actors have adopted a sophisticated attack chain known as ClickFix, which leverages deceptive social engineering lures and advanced steganography to deliver malware. The campaign begins with convincing fake human verification screens or Windows Update notifications that prompt users to open the Windows Run dialog and execute a command copied to their clipboard. This command initiates a multi-stage infection process, ultimately leading to the download and execution of malicious payloads concealed within PNG image files. The attackers use a custom steganographic algorithm to encode shellcode directly into the pixel data of these images, reconstructing and decrypting the payload entirely in memory to evade detection.
Security researchers have observed the ClickFix technique evolving, with newer lures mimicking legitimate Microsoft update processes in full-screen mode to increase credibility. The infection chain often results in the deployment of information-stealing malware, and in some cases, ransomware such as Qilin. The campaign highlights the growing sophistication of social engineering tactics and the use of steganography to bypass traditional security controls, posing a significant threat to organizations and individuals alike.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A separate ClickFix attack chain was reported that used fake robot-verification or Windows Update lures to get users to run commands, then used steganography in PNG images, mshta.exe, PowerShell, and a .NET loader to deliver LummaC2 and Rhadamanthys. The reporting revealed new technical details about how ClickFix was being used to hide payloads and evade detection.
Researchers identified a malware campaign using fake human-verification prompts branded as ClickFix to trick users and ultimately deploy Qilin ransomware on victim systems. The campaign showed continued use of deceptive web-based social engineering to deliver ransomware.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.