ClickFix Spin-Off Attack Bypasses Key Browser Safeguards
ID: 03a51e06-f4bd-5b9b-b2a1-b05211bfd5fa
STIX ID: report--03a51e06-f4bd-5b9b-b2a1-b05211bfd5fa
Feed Name: Dark Reading
Date Published: 2025-07-02
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
A security researcher disclosed "FileFix 2.0," a technique that abuses Chrome/Edge save-as behavior to omit Mark of the Web metadata and trick users into saving malicious HTML/HTA files that can execute arbitrary code (via mshta, PowerShell, etc.). The attack uses social-engineering lures (e.g., fake backup-code pages) to induce users to save and run files; mitigations include preventing mshta from running, monitoring for suspicious child processes, and training users to avoid saving/running files from untrusted pages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
