Wikiwand AI

ClickFix

Malware deployment method From Wikipedia, the free encyclopedia

ClickFix is a social engineering technique. It typically shows a popup over a webpage instructing the viewer to run a system command that will install malware.[1][2]

The first ClickFix version was discovered in October 2023.[3]

Research from Hudson Rock showed that ClickFix often forms a feedback loop, using credentials stolen by infostealers to compromise administrative accounts on legitimate websites and host new ClickFix lures.[4] In July 2026, researchers detailed an incident where stolen WordPress credentials led to a ClickFix campaign on an Artlist subdomain using Polygon smart contracts (EtherHiding) for dynamic payload routing.[5]

In March 2026, Apple added a mitigation to macOS to prevent ClickFix style attacks.[6][7] In April, a modified variant using the applescript:// URI scheme to bypass the use of the Terminal application was found.[8]

See also

Further reading

  • "Think before you Click(Fix): Analyzing the ClickFix social engineering technique". Microsoft Security Blog.

References

Related Articles

Timelines

Top Qs

Fact Checks