logo

ClickFix, CrashFix and the growing family of copy and paste attacks 

ID: f98d3cb1-7554-5032-9f40-2fccc7c60633

STIX ID: report--f98d3cb1-7554-5032-9f40-2fccc7c60633

Feed Name: Pen Test Partners Blog

Threat Score
75/100

Date Published: 2026-06-10

Date Updated: 2026-06-11

Author: Alex Wallace

...
...

This report describes an active and evolving family of social-engineering attacks (ClickFix, CrashFix, InstallFix, FileFix) that lure victims into copying and pasting commands which spawn hidden shells, drop or download payloads, and lead to credential theft, staging, persistence and exfiltration; it reviews observed variants (including macOS-focused campaigns and a malicious npm package), key forensic artefacts across Windows/macOS/Linux, and DFIR recommendations to detect and respond to such incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.