logo

That “Friendly” Prompt is ClickFix

ID: 485cf567-567b-5cc8-b2fd-7cee88c6930c

STIX ID: report--485cf567-567b-5cc8-b2fd-7cee88c6930c

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2026-03-25

Date Updated: 2026-04-28

...
...

This Huntress report details the "ClickFix" social-engineering trend where malicious webpages and lures trick users into executing copied commands in PowerShell, Run, or terminals, enabling stealthy loader and infostealer infections (examples include LummaC2). The technique bypasses traditional link/attachment detection by having victims run commands themselves, is reported as widespread in loader activity, and the report recommends focusing on resilience, rapid detection, and security awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.