logo

ClickFix malware attacks evolve with multi-OS support, video tutorials

ID: 6581e177-e074-5d3c-b5b0-56928ab6212b

STIX ID: report--6581e177-e074-5d3c-b5b0-56928ab6212b

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-11-06

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Push Security observations show ClickFix attacks have evolved to host fake verification pages that auto-detect the victim OS and present video tutorials, clipboard-copied commands, and countdown timers to pressure users into executing commands that fetch and run info-stealing payloads. These campaigns are spread via malvertising and compromised/SEO-poisoned sites and deliver OS-specific loaders (MSHTA, PowerShell, LOB binaries), with researchers warning of increasingly stealthy, browser-native variants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.