logo

New ClickFix Attack Exploits Windows Run Dialog and macOS Terminal to Deploy Malware

ID: 95570162-0b39-508d-9d92-071861d22583

STIX ID: report--95570162-0b39-508d-9d92-071861d22583

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Insikt Group describes the ClickFix campaign, a social‑engineering technique that coerces victims into executing obfuscated commands in Windows Run/PowerShell and macOS Terminal to fetch and run in‑memory malware (examples include NetSupport RAT and MacSync stealer). Analysts tracked five clusters since May 2024 using DOM hashing and content pivots to map malicious infrastructure; the report warns ClickFix is a resilient, widely adopted initial‑access method expected to persist through 2026 and recommends hardening native shells, applying execution controls, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.