Think before you Click(Fix): Analyzing the ClickFix social engineering technique
ID: 3bb46aaa-d04d-5397-ae0a-bfa2d9dcd810
STIX ID: report--3bb46aaa-d04d-5397-ae0a-bfa2d9dcd810
Feed Name: Microsoft Security
Date Published: 2025-08-21
Date Updated: 2026-04-28
Author: Microsoft Threat Intelligence and Microsoft Defender Experts
Microsoft Threat Intelligence describes the ClickFix social-engineering technique — phishing, malvertising, and compromised sites lure users to run copied commands (via Run dialog, PowerShell, Terminal) that fetch fileless or on-disk payloads. The report documents multiple active campaigns and malware families (Lumma Stealer, Lampion, AMOS, MintsLoader, Latrodectus, r77 rootkit, various RATs), provides IOCs (domains, IPs, URLs, hashes), detection/hunting queries, and mitigations including Defender XDR features, network protection, and user/OS hardening recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
