logo

Beware of Clickfix: ‘Fix Now’ and ‘Bot Verification’ Lures Deliver and Execute Malware

ID: 109d7efe-966e-5d57-b2eb-c99399726f09

STIX ID: report--109d7efe-966e-5d57-b2eb-c99399726f09

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2025-04-04

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

ClickFix is a browser-based social-engineering campaign that lures users with fake verification prompts (e.g., "Fix Now" or "Bot Verification") and leverages clipboard hijacking (instructing Windows+R, Ctrl+V, Enter) to execute mshta.exe or PowerShell commands that fetch and run remote scripts. Observed variants deliver information stealers such as Lumma and CryptBot, and researchers provide IOCs (domains, IPs, filenames, SHA-256 hashes) and recommended defenses including monitoring clipboard-based execution, blocking malicious domains, and enforcing MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.