ClickFix Social Engineering Campaigns Targeting Windows and macOS via Native System Tools
ClickFix Social Engineering Campaigns Targeting Windows and (TL-2026-0282), also tracked as ClickFix, is a high-severity phishing campaign, first published 2026-03-25. It is attributed to APT28 (Russia, North Korea) with high confidence, affects Microsoft Windows, maps to 10 MITRE ATT&CK techniques (T1027, T1059, T1071), and is covered by 9 detection rules and 38 indicators of compromise.
Key facts for TL-2026-0282
- Threat ID
- TL-2026-0282
- Also known as
- ClickFix
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-03-25
- Last reviewed
- 2026-03-25
- Attribution
- APT28
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia, North Korea
- Motivation
- ESPIONAGE
- Target sectors
- government, financial, technology, travel, real-estate, marketing, accounting, small-business
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 38
Malware and tooling in ClickFix Social Engineering Campaigns Targeting Windows and
Malware and tooling: MacSync, NetSupport RAT
Five distinct ClickFix social engineering clusters identified by Recorded Future Insikt Group, active since May 2024, exploit Windows and macOS by manipulating victims into executing malicious commands via native system tools (PowerShell, zsh, bash). Campaigns impersonate QuickBooks, Booking.com, Birdeye, and macOS system utilities, delivering NetSupport RAT and MacSync stealer. Nation-state groups APT28 (BlueDelta) and PurpleBravo (North Korea) are among operators using this technique.
How ClickFix Social Engineering Campaigns Targeting Windows and works
ClickFix is a rapidly evolving social engineering methodology that bypasses traditional browser-based security controls by shifting exploitation to user-assisted manual execution of obfuscated commands through native system tools. Five distinct operational clusters have been identified and tracked by Recorded Future's Insikt Group since May 2024, each employing unique brand impersonation lures but sharing a common four-stage kill chain: (1) obfuscated input via encoded/fragmented strings, (2) native execution through trusted system shells, (3) remote ingress from attacker infrastructure, and (4) in-memory execution to minimize forensic artifacts.
Cluster 1 (Intuit QuickBooks, January 2026-present) targets US tax season users with fraudulent QuickBooks verification pages. JavaScript copies obfuscated PowerShell commands to the victim's clipboard, which are then pasted into the Windows Run dialog. The PowerShell stager uses Invoke-RestMethod to contact nobovcs[.]com, downloads a script.ps1 stager, and deploys NetSupport RAT (neservice.exe) via password-protected 7z archives (password: "pppp"). Persistence is achieved through Startup folder shortcuts. The cluster uses distinctive "romantic naming" conventions for staging directories (Heart, Soul, Desire themes) and has recently pivoted to impersonating Zillow real estate services.
Cluster 2 (Booking.com, February 2026-present) uses counterfeit reCAPTCHA v2 challenges targeting travel agency users. The fake CAPTCHA presents identical "bucket" photo selection across all pages. Upon "verification," victims are directed to paste PowerShell commands (-NoProfile -ExecutionPolicy Bypass) that download NetSupport RAT via staging domains bkng-updt[.]com and checkpulses[.]com. C2 infrastructure uses chrm-srv[.]com and ms-scedg[.]com on IP 152.89.244.70.
Cluster 3 (Birdeye, May 2024-present) is the longest-running cluster, spoofing the Birdeye AI marketing platform across 40+ domains incorporating "bird" keywords. Infrastructure tracked via DOM hash pivoting on unique HTML titles and static images. All domains are Cloudflare-hosted. Payload delivery through alababababa[.]cloud, historically associated with Lumma Stealer and RedLine Stealer. JavaScript contains Cyrillic comments documenting PowerShell bypass techniques, suggesting Russian-speaking developers.
Cluster 4 (Dual-Platform Selection, March 2025-present) introduces OS detection to serve tailored lures for Windows and macOS targets. macOS infection chains use multi-stage encoding (hex to Base64 to ZSH execution) with the xxd utility (xxd -r -p) for hex decoding — a rare pattern in legitimate troubleshooting that serves as a high-fidelity behavioral IOC. curl flags (-kfsSL) bypass TLS verification while suppressing errors. The MacSync information stealer is deployed via nohup for background persistence. C2 infrastructure uses octopox[.]com and joeyapple[.]com behind Cloudflare.
Cluster 5 (macOS Storage Cleaning, December 2025-present) targets macOS users with counterfeit system optimization prompts ("Find and remove temporary system files"). Uses similar multi-stage encoded command chains as Cluster 4, deploying payloads in-memory with nohup backgrounding.
The ClickFix methodology has been adopted by nation-state actors including APT28/BlueDelta (Russia) and PurpleBravo (North Korea), elevating it from a purely criminal technique to a state-sponsored initial access vector. The standardized four-stage pattern — obfuscated input, native execution, remote ingress, in-memory execution — represents a significant evolution in social engineering that bypasses endpoint detection by leveraging user trust in system prompts. Recorded Future assesses with high confidence that ClickFix will remain a primary initial access vector throughout 2026, with future iterations expected to incorporate granular browser fingerprinting, conditional payload serving, and increasingly resilient obfuscation.
MITRE ATT&CK techniques used in TL-2026-0282
defense-evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
discovery
T1082 System Information Discovery
persistence
T1547 Boot or Logon Autostart Execution
initial-access
Affected products and versions in ClickFix Social Engineering Campaigns Targeting Windows and
- Microsoft — Windows
Vulnerable versions: 10; 11; Server 2019; Server 2022 - Apple — macOS
Vulnerable versions: Ventura; Sonoma; Sequoia
Remediation for ClickFix Social Engineering Campaigns Targeting Windows and
Immediate actions
- Block all identified IOC domains and IPs at perimeter firewalls and DNS sinkholes
- Deploy emergency Splunk/KQL detections for PowerShell Invoke-RestMethod + Invoke-Expression combination
- Alert SOC teams to monitor for xxd -r -p and nohup curl patterns on macOS endpoints
- Block AS215439 (PLAY2GO), AS57523 (Chang Way), AS200593 (Prospero), AS41745 (Baykov) at network edge
Workarounds
- Restrict PowerShell execution policy to AllSigned via GPO
- Enable System Integrity Protection (SIP) on all macOS endpoints
- Deploy browser extensions that block clipboard manipulation via JavaScript
- Implement network-level blocking of password-protected archive downloads
Longer-term hardening
- Disable Windows Run dialog via Group Policy Objects (GPOs) for non-administrative users
- Enforce PowerShell Constrained Language Mode (CLM) across all Windows endpoints
- Deploy AppLocker or Windows Defender Application Control (WDAC) to prevent LOLBin misuse
- Implement MDM-enforced Terminal restrictions on macOS fleet
- Conduct targeted social engineering simulations emphasizing manual command execution dangers
- Deploy EDR with behavioral detection for clipboard-to-execution chains
- Monitor DOM hashes and page titles for brand impersonation campaigns
Timeline of ClickFix Social Engineering Campaigns Targeting Windows and
- Cluster 3 (Birdeye) begins operations — first observed ClickFix campaign spoofing Birdeye AI marketing platform across 40+ bird-keyword domains
- Cluster 4 (Dual-Platform Selection) observed — introduces OS detection to serve tailored Windows/macOS lures and deploys MacSync stealer
- Cluster 5 (macOS Storage Cleaning) begins operations — targets macOS users with counterfeit system optimization prompts
- Cluster 1 (Intuit QuickBooks) launches — targets US tax season with fraudulent QuickBooks verification pages delivering NetSupport RAT
- Cluster 2 (Booking.com) begins operations — uses counterfeit reCAPTCHA v2 challenges to target travel agency users
- Cluster 4 C2 domains joeyapple[.]com and octopox[.]com first registered and active behind Cloudflare
- Last observed activity for Cluster 4 C2 domains octopox[.]com and joeyapple[.]com
- All five ClickFix clusters confirmed actively operating with continued infrastructure expansion and nation-state adoption by APT28 and PurpleBravo
- Recorded Future Insikt Group publishes comprehensive ClickFix campaign analysis documenting all five clusters with full IOC sets
- As of 2026-05-29, ClickFix remains a top live initial-access technique: Microsoft (2026-05-06) reported fresh fake-macOS-utility lures dropping MacSync/AMOS infostealers, Malwarebytes flagged 700+ hijacked sites in May, and SmartApeSG/EVALUSION continue dropping NetSupport RAT. No CVE to patch; APT28 and PurpleBravo adoption persists.
Sources cited for ClickFix Social Engineering Campaigns Targeting Windows and
- Recorded Future Insikt Group: ClickFix Campaigns Targeting Windows and macOS
- MITRE ATT&CK T1204.004 - User Execution: Malicious Copy and Paste
- MITRE ATT&CK T1059.001 - Command and Scripting Interpreter: PowerShell
- NetSupport RAT Abuse in Campaigns
- APT28/BlueDelta Threat Profile - MITRE ATT&CK
- Proofpoint: ClickFix Social Engineering Technique Analysis
- Sekoia: ClickFix Tactic Adoption by Nation-State Actors
More in phishing
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification
Detection coverage for TL-2026-0282
As of 2026-03-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0282 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.