logo

Fix the Click: Preventing the ClickFix Attack Vector

ID: bec401d6-b5b0-561b-a5a6-22426c545bf8

STIX ID: report--bec401d6-b5b0-561b-a5a6-22426c545bf8

Feed Name: Palo Alto Networks Unit 42

Threat Score
78/100

Date Published: 2025-07-10

Date Updated: 2026-04-28

Author: Rem Dudas and Noa Dekel

...
...

Unit 42 documents a surge in "ClickFix" pastejacking campaigns in 2025 that trick users into pasting malicious commands (via Win+R and Win+X) to deliver NetSupport RAT, Latrodectus, and Lumma Stealer; the report maps infection chains, analyzes a DLL-based NetSupport loader, provides extensive IoCs (hashes, domains, C2 URLs), and offers hunting and mitigation guidance for detection via RunMRU, event logs, and EDR telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.