logo

Meet IClickFix: a widespread WordPress-targeting framework using the ClickFix tactic

ID: 68bca0d4-5770-5eec-b004-a89fc96662a7

STIX ID: report--68bca0d4-5770-5eec-b004-a89fc96662a7

Feed Name: Sekoia.io Blog

Threat Score
75/100

Date Published: 2026-01-29

Date Updated: 2026-04-29

Author: Quentin Bourgue, Amaury G. and Sekoia TDR

...
...

Sekoia.io TDR uncovered and analyzed IClickFix, a multi-stage JavaScript framework active since late 2024 that injects an ic-tracker-js tag into compromised WordPress sites (over 3,800 observed) to display a fake Cloudflare Turnstile ClickFix lure; victims are tricked into pasting a clipboard command that runs a PowerShell dropper, resulting in the deployment of NetSupport RAT (and historically Emmenhtal Loader/XFiles Stealer). The report includes technical analysis of the injection and redirection chain (YOURLS-based TDS), infection stages, full IoCs (domains, IPs, file hashes), and YARA rules to detect the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.