ClickFix: The High-ROI “Living-off-the-Land” Trap Sweeping Windows and macOS
ID: 8e65717a-b174-5551-9117-149a7009569f
STIX ID: report--8e65717a-b174-5551-9117-149a7009569f
Feed Name: securityonline.info
This report details ClickFix, a high-ROI social-engineering technique that prompts users to manually run malicious commands (via Windows Run or macOS Terminal) to execute malware in-memory and evade typical browser and endpoint controls; it outlines five sector-targeted clusters (e.g., QuickBooks, faux reCAPTCHA, macOS storage cleaning), notes use by access brokers and APT actors like BlueDelta, and recommends behavioral hardening measures including disabling Run, PowerShell CLM, macOS MDM controls, and focused user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
