logo

New ClickFix Scam Tricks Users Into Mapping Hacker-Controlled Drives

ID: cdf301bf-4dbc-56c8-b6b7-7e3204af5ec8

STIX ID: report--cdf301bf-4dbc-56c8-b6b7-7e3204af5ec8

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

A ClickFix phishing campaign uses a clipboard trick (prompting users to run Win+R and paste a hidden command) to execute 'net use', map a remote drive, and download a legitimate-signed app (WorkFlowy) whose asar archive has been swapped with malicious Node.js code; the payload runs in-process with user privileges, avoids writing files to disk, generates a victim ID, and beacons to attacker-controlled servers, leaving only RunMRU registry entries as reliable forensic traces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.