Researchers reported that ClickFix campaigns are increasingly using fake Google, Cloudflare, reCAPTCHA, and Google Meet verification pages to trick users into manually running malicious PowerShell and shell commands. Analysis of roughly 3,000 live payloads found operators now rely on backend APIs to generate unique, obfuscated commands on demand, while reusing the same malware through different wrappers. The technique has expanded sharply, with one report citing a 517% increase from late 2024 into the first half of 2025 and Microsoft attributing 47% of initial-access cases seen by its Defender Experts team in 2025 to ClickFix activity.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Malwarebytes reported that fake Google and Cloudflare verification page campaigns using the ClickFix technique have been active since at least late 2025. The campaigns used recurring infrastructure and tradecraft while distributing multiple malware families.
Malwarebytes highlighted an infection chain in which a trojanized Franz messaging app fetched a previously undocumented loader dubbed ResiLoader. The loader was described as disabling security tools, establishing persistence, and deploying StealC via process hollowing.
Malwarebytes documented evolving ClickFix campaigns that used fake Google and Cloudflare verification pages to trick users into running malicious PowerShell commands. The company said the operators distributed malware including HijackLoader, StealC, Remus, Amatera Stealer, CastleLoader, NetSupport, a Rust-based stealer, and a Deno-based PowerShell stealer chain.
Bert-Jan Pals also identified a newer ClickFix delivery method in which a benign-looking clipboard command moves and unpacks a downloaded archive from the Downloads folder. The approach helps evade AMSI inspection because the malicious payload is stored separately from the pasted command.
Research by Bert-Jan Pals found that modern ClickFix campaigns use backend APIs to generate unique, obfuscated payload commands on demand. The analysis was based on roughly 3,000 live ClickFix payloads and showed that different wrappers often delivered the same malware.
Proofpoint linked state-backed groups including APT28, MuddyWater, and Kimsuky to campaigns using the ClickFix technique. This showed the method had expanded beyond cybercriminal operations.
Microsoft stated that ClickFix accounted for 47% of the initial-access cases seen by its Defender Experts team in 2025. The figure underscored how prominent the technique had become in real-world intrusions.
According to the cited research, ESET observed a 517% increase in ClickFix activity from late 2024 into the first half of 2025. This marked a major growth phase for the social-engineering technique.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 63 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcethehackernews.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.