Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums.
Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
On July 23, ReliaQuest reported that part of the CaptiveCrunch activity used doppelganger domains to abuse the Microsoft Entra ID device code authentication flow. Microsoft’s reporting cited this as part of the broader Storm-2945 campaign.
Microsoft observed Storm-2945 conducting the CaptiveCrunch campaign since early May 2026. The actor manipulated DNS and HTTP traffic on hospitality and other captive-portal-served networks worldwide to redirect travelers to attacker-controlled infrastructure for phishing and malware delivery.
Microsoft said the Lampion ClickFix campaign was still active as of June 2025 and had expanded beyond Portugal. Later targeting included organizations in Switzerland, Luxembourg, France, Hungary, and Mexico across government, education, transportation, and financial services sectors.
Microsoft observed a June 2025 phishing campaign impersonating the US Social Security Administration. It used a compromised Brazilian domain and a Google Ads redirect chain to deliver ScreenConnect through a spoofed SSA-themed ClickFix page.
Microsoft reported that a ClickFix campaign active since late May 2025 targeted macOS users with Spectrum-themed lures. The campaign delivered Atomic macOS Stealer (AMOS).
In May 2025, Microsoft identified a ClickFix campaign delivering Lampion-themed infection stages against Portuguese organizations in government, finance, and transportation. The phishing emails carried ZIP files with HTML that redirected victims to a fake Portuguese tax authority site.
In April 2025, Microsoft observed a malvertising campaign redirecting users from free or pirated movie streaming sites to ClickFix pages. The activity delivered Lumma Stealer and used intermediate HTA scripts renamed with media extensions such as .mp3 and .mp4.
Microsoft observed Storm-0426 launch a phishing campaign in March 2025 targeting users in Germany. The emails used payment and invoice lures and redirected victims through compromised sites and the Prometheus TDS to install MintsLoader.
In early March 2025, Microsoft observed Storm-0249 move from email-based delivery to compromising legitimate websites, likely through WordPress vulnerabilities. The actor then used ClickFix pages to deliver Latrodectus or other initial-access malware.
In May 2024, Microsoft observed a Storm-1607 campaign sending tens of thousands of payment- and invoice-themed phishing emails to organizations in the United States and Canada. The activity attempted to deliver DarkGate via ClickFix-style lures.
Microsoft first observed ClickFix use between March and June 2024 in Storm-1607 email campaigns. These phishing emails used HTML attachments to try to install the DarkGate loader.
Microsoft reported that an underground market for ClickFix builders had been active on hacker forums since late 2024. Subscriptions were advertised at roughly $200 to $1,500 per month.
Since early 2024, Microsoft said it has helped multiple customers address ClickFix campaigns delivering payloads such as Lumma Stealer. The company also observed the technique targeting thousands of devices globally each day over the following year.
A Malware-Traffic-Analysis.net report documented a SmartApeSG ClickFix infection chain in which injected traffic on a compromised website led victims to run clipboard-pasted commands from a fake CAPTCHA or human verification page. The commands fetched an HTA downloader from deltaode[.]com, which retrieved a ZIP archive used for DLL side-loading of an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalware-traffic-analysis.net
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.