PULSE NAME
ClickFix Campaigns Targeting Windows and macOS
WHITE AlienVault 2026-03-25 Modified: 2026-03-25
141
IOCs
HIGH VOLUME
Insikt Group identified five distinct clusters using the ClickFix social engineering technique for initial access. These clusters impersonate various services like Intuit QuickBooks and Booking.com, demonstrating operational variance but similar core techniques. ClickFix manipulates victims into executing malicious commands within native system tools, bypassing traditional security controls. The methodology has become a standardized template for cybercriminals and APT groups. Campaigns target diverse sectors and use sophisticated obfuscation and living-off-the-land tactics. Defenders are advised to implement aggressive behavioral hardening and user awareness training to mitigate these threats.
Indicators of Compromise (3 / 141 total)
All IPv4 FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 4b261a6adf6e0c952b5fb837091ff023 2026-03-25
FileHash-MD5 58712aacf6b0f8149c066bda3a034fc3 2026-03-25
FileHash-MD5 95c6515d88e9ea48a9b949a81c1dac4e 2026-03-25