logo

Proactive ClickFix Threat Hunting with Hunt.io

ID: 901925dd-9517-54a4-bed7-89992d61f06d

STIX ID: report--901925dd-9517-54a4-bed7-89992d61f06d

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report describes the emergence and observed usage of "ClickFix," a browser-based social-engineering technique that hijacks the clipboard and tricks users into pasting and executing malicious commands (via mshta.exe, PowerShell, or JavaScript) under the guise of CAPTCHA or security prompts; researchers identified multiple active domains, payload delivery chains (including Lumma and CryptBot), credential-phishing variants targeting Zoho, fileless PowerShell staging, and provided domain/IP/ASN and file-hash IOCs to help defenders hunt and block activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.