logo

ClickFix: How to Infect Your PC in Three Easy Steps

ID: 60b839fd-33fc-5010-b0ef-28a068aac987

STIX ID: report--60b839fd-33fc-5010-b0ef-28a068aac987

Feed Name: Krebs on Security

Threat Score
70/100

Date Published: 2025-03-14

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

**Executive Summary:** The report details the "ClickFix" scam — a widespread phishing/campaign technique that lures users with fake CAPTCHA or error popups and instructs them to press a sequence of keys (Win+R, Ctrl+V, Enter) to execute mshta.exe, resulting in the download and execution of multiple credential‑stealing malware families (e.g., XWorm, Lumma stealer, VenomRAT, AsyncRAT, Danabot, NetSupport RAT); targets include hospitality and healthcare organizations, and delivery occurs via compromised/malicious websites and phishing emails with HTML attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.