Researchers and Microsoft documented multiple ClickFix intrusion chains that trick users into pasting malicious commands after fake browser errors or security prompts, then abuse native tools and staged scripting environments to deliver malware. In one Windows chain, a caret-obfuscated command entered through the Run dialog used the finger protocol over TCP/79 to fetch a batch stage, killed explorer.exe, copied and renamed the native curl.exe, downloaded the legitimate IronPython 3.4.2 release from GitHub disguised as a PDF, extracted it with tar.exe, and launched an encoded Python payload. That payload decoded layered content, disabled TLS certificate verification, contacted artides[.]net for in-memory execution, beaconed to claudeam[.]com, and ended with RemoteLibraryInjection into explorer.exe plus installation of a global low-level keylogger.
Microsoft separately described the CrashFix variant, which used a fake Chrome extension impersonating uBlock Origin Lite to establish foothold, intentionally crashed the browser, and then prompted victims to run commands that renamed finger.exe and fetched obfuscated PowerShell. On domain-joined systems, the activity dropped a portable WinPython environment and the ModeloRAT Python remote access trojan, established persistence through a Run key, and in related cases created a scheduled task named SoftwareProtection for repeated execution. Additional reporting showed the same broader ClickFix ecosystem targeting Windows, macOS, and Linux, including a Perl-based Pearl Stealer that harvested browser, wallet, document, and Apple Notes data, stole macOS passwords, and exfiltrated files after OS-specific clipboard-delivered commands downloaded payloads from attacker infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
ShroudCloud reported that the intrusion matched the broader ClickFix IronPython loader family, one of three ClickFix families documented using finger as a delivery vector. The report noted that no named threat actor had been publicly attributed to this cluster.
On February 5, 2026, Microsoft published technical details on CrashFix, including its fake extension, finger.exe abuse, PowerShell staging, and ModeloRAT deployment. The company also released mitigations, hunting queries, and indicators of compromise.
In January 2026, Microsoft Defender Experts identified a new evolution of the ClickFix campaign dubbed 'CrashFix.' Microsoft said the variant intentionally crashes victims' browsers and socially engineers them into running malicious commands to restore functionality.
The renamed IronPython interpreter decoded an embedded Python stage that disabled TLS certificate verification and fetched additional code from artides[.]net for in-memory execution. About five minutes after the initial paste, the endpoint recorded RemoteLibraryInjection into restarted explorer.exe and installation of a global low-level keylogger.
A ClickFix intrusion began with a caret-obfuscated command pasted into the Windows Run dialog that used finger.claudeam.com over TCP/79 to retrieve and execute a batch script. The script killed Explorer, copied and renamed curl.exe, downloaded the legitimate IronPython 3.4.2 release disguised as a PDF, extracted it, and launched a renamed IronPython interpreter.
On domain-joined hosts, CrashFix downloaded a portable WinPython package and a Python RAT Microsoft called ModeloRAT. The malware beaconed over HTTP, established persistence with a Run key, and downloaded an additional Python payload from Dropbox.
In observed activity, the campaign copied finger.exe to a temporary directory as ct.exe and used it to retrieve a large charcode payload from 69[.]67[.]173[.]30. The resulting obfuscated PowerShell downloaded script.ps1, performed environment checks, and selectively deployed follow-on malware to domain-joined systems.
CrashFix commonly began with a malicious ad for an ad blocker that redirected victims to the legitimate Chrome Web Store, where a fake extension impersonating uBlock Origin Lite was installed. The extension sent a UUID to attacker-controlled infrastructure and later triggered a browser denial-of-service and fake warning.
Pearl Stealer downloaded additional components from 213.108.198[.]227, established persistence through shell startup files, inventoried browser, wallet, and document data, and exfiltrated stolen files to attacker infrastructure. On macOS it also prompted for the victim's password and used it to install stronger persistence, while on Linux it additionally downloaded and ran a Python-based component named data_extracter.
A ClickFix campaign used a dedicated malicious website that detected Windows, macOS, and Linux and copied platform-specific commands to victims' clipboards. On macOS and Linux, the commands fetched Perl payloads from cloudflare.blazing-cloud[.]com, leading to deployment of the previously undocumented Pearl Stealer.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
shroudcloud.io
Open sourcemicrosoft.com
Open sourcermceoin.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.