logo

ClickFix: The Social Engineering Technique Hackers Use to Manipulate Victims

ID: 69e90240-66ab-508a-b699-3a14e84aaea1

STIX ID: report--69e90240-66ab-508a-b699-3a14e84aaea1

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2025-03-13

Date Updated: 2026-04-28

...
...

This Group-IB report analyzes the ClickFix (aka ClearFix) social-engineering technique—fake CAPTCHAs and “Fix” prompts that auto-copy malicious PowerShell to the clipboard and trick users into pasting it into the Windows Run dialog—detailing an August 2024 incident where a SMOKESABER downloader fetched bravo.zip containing the LummaC2 infostealer, providing indicators, delivery methods (malvertising, phishing, social spam), observed APT usage, detection/hunting guidance, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.