logo

Meet IClickFix: a widespread framework using the ClickFix tactic

ID: b1e3dd05-2c2c-5813-832c-55a1ccbdf166

STIX ID: report--b1e3dd05-2c2c-5813-832c-55a1ccbdf166

Feed Name: Sekoia.com

Threat Score
75/100

Date Published: 2026-01-29

Date Updated: 2026-07-20

...
...

This report details the IClickFix campaign (active since late 2024), where attackers compromised over 3,800 WordPress sites to inject an obfuscated JavaScript framework that replaces pages with a ClickFix (fake CAPTCHA) lure; victims who execute the provided command download and run obfuscated PowerShell droppers that deploy NetSupport RAT (and previously Emmenhtal Loader/XFiles Stealer). The analysis includes infection chain stages, YARA rules, IoCs (domains, IPs, file hashes), evidence of YOURLS abused as a TDS, and recommendations for monitoring and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.