logo

ClickFix: The Copy-Paste Attack That Turns You Into Your Own Worst Enemy

ID: 5c097be0-22c4-5fae-bfe3-540bb2bcca75

STIX ID: report--5c097be0-22c4-5fae-bfe3-540bb2bcca75

Feed Name: NoHackie

Threat Score
85/100

Date Published: 2026-02-15

Date Updated: 2026-04-19

...
...

ClickFix is a widespread social-engineering technique that persuades victims to paste attacker-supplied commands into system terminals or browser consoles, bypassing traditional defenses and enabling malware installation, credential and wallet theft, ransomware, and other post-compromise activity. The report details rapid growth (500%+ detections), cross-platform targeting (Windows, macOS, Linux), adoption by nation-state groups and criminal services, commercial toolkits (ErrTraffic), and a Pastebin-based JavaScript variant that hijacks cryptocurrency swaps by modifying rates and replacing wallet addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.