PULSE NAME
Fix the Click: Preventing the ClickFix Attack Vector
WHITE AlienVault 2025-07-10 Modified: 2025-08-09
85
IOCs
HIGH VOLUME
This article discusses the rising threat of ClickFix, a social engineering technique used by threat actors to trick victims into executing malicious commands under the guise of quick fixes for computer issues. The technique has been observed in campaigns distributing various malware, including NetSupport RAT, Latrodectus, and Lumma Stealer. ClickFix lures often use clipboard hijacking and can bypass standard detection controls. The article provides case studies of recent campaigns, hunting tips for detecting ClickFix infections, and recommendations for proactive defense measures. It emphasizes the importance of user education and implementing robust security controls to mitigate this evolving threat.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
NetSupport RAT Latrodectus Lumma Stealer
Indicators of Compromise (8 / 85 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0bd717cd72246ba4b246245e85161a8162d62c19 2025-07-10
FileHash-SHA1 42cc90a18e326003ad3abc8942647e2564b441ca 2025-07-10
FileHash-SHA1 6b0c0a35d0020700cc2baf744eb3b2a250945bbf 2025-07-10
FileHash-SHA1 b3db22bc6f7c9c1fb7e7183821d6cd1cabaa73ce 2025-07-10
FileHash-SHA1 e119de06dc6535e9086c01619dc9d07d0edf18ed 2025-07-10
FileHash-SHA1 94d786cd03f8dff56e4f97f5817894c482d5f6fa 2025-07-10
FileHash-SHA1 cca2b2aa7e21c655991686fc99549ef39a123ece 2025-07-10
FileHash-SHA1 dac282410c0ac6648c859e74d5f114b3dae57a68 2025-07-10