logo

New ClickFix ‘Word Online’ Message Tricks Users into Installing DarkGate Malware

ID: ca3b1b5c-83d9-582c-9917-b5512bb9e491

STIX ID: report--ca3b1b5c-83d9-582c-9917-b5512bb9e491

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-17

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

This report describes the "ClickFix" social-engineering campaign that mimics a missing browser extension error to persuade users to open PowerShell and paste a malicious "fix" command copied by the webpage; the command fetches a dark.hta file which drops an AutoIt executable and an encrypted payload decrypted with DES to install the DarkGate remote access trojan, enabling full system compromise and C2 communication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.