logo

'JackFix' Attack Circumvents ClickFix Mitigations

ID: bf6ec123-ad4c-582f-87fd-4c5111953ea4

STIX ID: report--bf6ec123-ad4c-582f-87fd-4c5111953ea4

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2025-11-25

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

JackFix is a ClickFix-derived phishing campaign that lures users to fake sites, displays a convincing full-screen fake Windows crash/lock to panic victims, and coerces them into executing commands that fetch an obfuscated PowerShell loader; that loader disables Defender protections and deploys multiple commercial infostealers (Rhadamanthys, Vidar 2.0, RedLine, Amadey). The campaign includes evasive techniques such as runtime reconstruction of payloads and content-based URL gating to avoid analysis and detection, and has generated hundreds of VirusTotal reports across the US and Europe; mitigation advice includes disabling Windows Run for users and limiting browser full-screen capability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.