logo

Understanding the ClickFix attack

ID: a538afcb-9cd7-5c99-9269-907aaab24c77

STIX ID: report--a538afcb-9cd7-5c99-9269-907aaab24c77

Feed Name: Dr.Web News

Threat Score
65/100

Date Published: 2025-10-24

Date Updated: 2026-04-27

...
...

**ClickFix** is a clipboard-based social-engineering attack where malicious or spoofed webpages copy scripts into a victim's clipboard and prompt them to paste and execute those commands (e.g., in elevated PowerShell), enabling remote command-and-control, payload delivery, and post‑exploitation activity; the report describes the attack flow, common lures (fake updates and CAPTCHAs), detection challenges (antivirus often only sees post‑execution behavior), and recommends early mitigations such as clipboard monitoring, network/trafic analysis, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.