logo

ClickFix: YARA Rules Catch What AV Misses

ID: d2e675b6-c3f5-5870-bf9d-9b3e9ae4933a

STIX ID: report--d2e675b6-c3f5-5870-bf9d-9b3e9ae4933a

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-04-30

Author: Toni Dujmović

...
...

ClickFix is an active social‑engineering campaign that uses fake CAPTCHA/verification pages to write malicious PowerShell commands to victims' clipboards and cause in‑memory execution; the report introduces a YARA rule that identified 283 samples (many undetected by AV) and demonstrates automated decoding and IOC extraction for both plaintext and Base64‑encoded payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.