logo

New ClickFix Attack Leverage Windows Run Dialog Box and macOS Terminal to Deploy Malware

ID: ebba91c6-8c30-50a3-a97d-cb199690ccb3

STIX ID: report--ebba91c6-8c30-50a3-a97d-cb199690ccb3

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-03-26

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Recorded Future researchers describe the resurgence and rapid expansion of the ClickFix social-engineering technique, where users are lured into pasting hidden commands into Windows Run or macOS Terminal to execute in-memory malware (NetSupport RAT, various stealers, MacSync). The report covers five distinct clusters that impersonate trusted services, use living-off-the-land techniques and native shells to avoid detection, lists example infrastructure and themes, and provides mitigation guidance including disabling the Run dialog, applying PowerShell/AppLocker controls, restricting terminal access, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.