logo

ClickFix tactic: Revenge of detection

ID: 97d5daed-d055-5729-b152-e72b1fa0b1b6

STIX ID: report--97d5daed-d055-5729-b152-e72b1fa0b1b6

Feed Name: Sekoia.io Blog

Threat Score
70/100

Date Published: 2024-11-05

Date Updated: 2026-04-29

Author: Jeremy Scion and Sekoia TDR

...
...

ClickFix is an emerging social-engineering tactic that coerces victims via fake Google Meet or reCAPTCHA pages to open the Run dialog and paste/execute malicious mshta or PowerShell commands, enabling download and execution of payloads (including infostealers such as Amos Stealer). The report documents Windows and macOS infection chains, abuse of legitimate tools (mshta, bitsadmin, PowerShell), provides endpoint and network detection rules and correlation recipes, and notes usage by multiple intrusion sets including TA571 and reported attribution to APT28.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.