logo

Think before you Click(Fix): Analyzing the ClickFix social engineering technique

ID: 3bb46aaa-d04d-5397-ae0a-bfa2d9dcd810

STIX ID: report--3bb46aaa-d04d-5397-ae0a-bfa2d9dcd810

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2025-08-21

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence and Microsoft Defender Experts

...
...

Microsoft Threat Intelligence describes the ClickFix social-engineering technique — phishing, malvertising, and compromised sites lure users to run copied commands (via Run dialog, PowerShell, Terminal) that fetch fileless or on-disk payloads. The report documents multiple active campaigns and malware families (Lumma Stealer, Lampion, AMOS, MintsLoader, Latrodectus, r77 rootkit, various RATs), provides IOCs (domains, IPs, URLs, hashes), detection/hunting queries, and mitigations including Defender XDR features, network protection, and user/OS hardening recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.