PULSE NAME
Fix the Click: Preventing the ClickFix Attack Vector
WHITE AlienVault 2025-07-10 Modified: 2025-08-09
85
IOCs
HIGH VOLUME
This article discusses the rising threat of ClickFix, a social engineering technique used by threat actors to trick victims into executing malicious commands under the guise of quick fixes for computer issues. The technique has been observed in campaigns distributing various malware, including NetSupport RAT, Latrodectus, and Lumma Stealer. ClickFix lures often use clipboard hijacking and can bypass standard detection controls. The article provides case studies of recent campaigns, hunting tips for detecting ClickFix infections, and recommendations for proactive defense measures. It emphasizes the importance of user education and implementing robust security controls to mitigate this evolving threat.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
NetSupport RAT Latrodectus Lumma Stealer
Indicators of Compromise (12 / 85 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0f9411596e254d60d181e1c2e79cb2d5 2025-07-10
FileHash-MD5 58995e4bf1318a44d775d7b273de4933 2025-07-10
FileHash-MD5 5bc51a4e118f2a8208d90b5f35a0af40 2025-07-10
FileHash-MD5 5e65dbaf6a158b83f280b529368ab428 2025-07-10
FileHash-MD5 bbb2eb34fed468b8ec5cd0be88f9acbb 2025-07-10
FileHash-MD5 164d8d82c41c4e1b871bc21802a18154 2025-07-10
FileHash-MD5 626890a630d8418ea6c2ef0fa17f02ef 2025-07-10
FileHash-MD5 7efc089d5da740a994d1472af48fc689 2025-07-10
FileHash-MD5 9f3018dd52fce55b302874ed24b0fd18 2025-07-10
FileHash-MD5 a384eb33be4f98c4df33ac1b99d1c417 2025-07-10
FileHash-MD5 a5a2932dc7f143499b865f8580102688 2025-07-10
FileHash-MD5 cfb8c6a16eace9730a846a11f6e70dda 2025-07-10