logo

ClickFix Campaigns Targeting Windows and macOS

ID: 44f8d1dc-8d08-5444-b56e-ba500270c5d0

STIX ID: report--44f8d1dc-8d08-5444-b56e-ba500270c5d0

Feed Name: Recorded Future Blog

Threat Score
78/100

Date Published: 2026-03-25

Date Updated: 2026-04-29

...
...

Insikt Group documents the ClickFix social-engineering technique across five distinct clusters (impersonating QuickBooks, Booking.com, Birdeye, dual-platform selection, and macOS storage cleaning) that coerce victims into executing obfuscated commands in native shells to download and run payloads (notably NetSupport RAT and multiple information stealers); the report provides detailed TTP analysis, extensive IOCs (domains, IPs, SHA256 hashes), observed infrastructure patterns, and recommended mitigations such as disabling the Windows Run dialog, enforcing PowerShell Constrained Language Mode, and operationalizing HTML/content threat monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.