Netskope Threat Labs

ClickFix

ATP Sandbox Adv. HeuristicsAVNetskope IPS

ClickFix is a social engineering technique in which cyberattackers present a fake CAPTCHA, browser update, or error message and instruct users to copy an obfuscated command and paste it into the Windows Run dialog or a terminal. Because users run the command themselves, the attack bypasses email filters, browser sandboxes, and other defenses that block malicious file downloads, and it has become a leading delivery method for infostealers such as Lummastealer and Amatera since late 2024.

First seen
October 2024
Last seen
October 2026
Clickfix
Alert Name
Document-HTML.Malware.ClickFix
Document-HTML.Trojan.ClickFix
Generic.JS.Clickfix.1.0022DC61
Generic.JS.Clickfix.1.01441D81
Generic.JS.Clickfix.1.0145628D
Generic.JS.Clickfix.1.01E8A1DE
Generic.JS.Clickfix.1.02FE4744
Generic.JS.Clickfix.1.03023234
Generic.JS.Clickfix.1.03403FF3
Generic.JS.Clickfix.1.0447F4FC
Signature Name
ET ATTACK_RESPONSE ClickFix CnC Response (Click Logged Successfully)
ET ATTACK_RESPONSE ClickFix Related Payload Inbound
ET ATTACK_RESPONSE ClickFix Webpage Inbound
ET ATTACK_RESPONSE Likely ClickFix Related Staging Domain
ET ATTACK_RESPONSE Observed ClickFix Landing Page Inbound
ET ATTACK_RESPONSE Observed ClickFix Powershell Delivery Page (Portuguese)
ET ATTACK_RESPONSE Observed ClickFix Powershell Delivery Page Inbound
ET EXPLOIT_KIT ClickFix Activity (Fetch for Javascript Loader) M1
ET EXPLOIT_KIT ClickFix Activity (Fetch for Javascript Loader) M2
ET EXPLOIT_KIT ClickFix Activity (Fetch for Javascript Loader) M3