Proactive ClickFix Threat Hunting with Hunt.io
ID: 901925dd-9517-54a4-bed7-89992d61f06d
STIX ID: report--901925dd-9517-54a4-bed7-89992d61f06d
Feed Name: Hunt.io Blog
This report describes the emergence and observed usage of "ClickFix," a browser-based social-engineering technique that hijacks the clipboard and tricks users into pasting and executing malicious commands (via mshta.exe, PowerShell, or JavaScript) under the guise of CAPTCHA or security prompts; researchers identified multiple active domains, payload delivery chains (including Lumma and CryptBot), credential-phishing variants targeting Zoho, fileless PowerShell staging, and provided domain/IP/ASN and file-hash IOCs to help defenders hunt and block activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
