logo

Clickfix Scams Use ‘Fix Now’ and ‘Bot Verification’ Baits to Deploy Malware

ID: 5e3d2692-e854-5b35-af59-d78fa51aa3d4

STIX ID: report--5e3d2692-e854-5b35-af59-d78fa51aa3d4

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-04-04

Date Updated: 2026-04-13

Author: Mandvi

...
...

The report describes "ClickFix", a browser-based social-engineering technique that lures users with CAPTCHA- or verification-style prompts and hijacks the clipboard to execute encoded PowerShell/mshta/javascript payloads, enabling credential theft and deployment of information-stealing malware (examples include Lumma and CryptBot). Multiple live domains, IPs, and file hashes are provided as IoCs, and the report recommends monitoring clipboard-related script execution, logging PowerShell activity, blocking lure-style domains, and enforcing MFA to mitigate impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.