ClickFix Social Engineering Campaigns Targeting Windows and macOS via Native System Tools — Threadlinqs Intelligence
As of 2026-05-30, ClickFix Social Engineering Campaigns Targeting Windows and macOS via Native System Tools is a high-severity phishing threat attributed to APT28 (Russia / North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 38 indicators of compromise.
Threat ID: TL-2026-0282 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: APT28 · Russia / North Korea · ESPIONAGE
Five distinct ClickFix social engineering clusters identified by Recorded Future Insikt Group, active since May 2024, exploit Windows and macOS by manipulating victims into executing malicious
ClickFix is a rapidly evolving social engineering methodology that bypasses traditional browser-based security controls by shifting exploitation to user-assisted manual execution of obfuscated commands through native system tools. Five distinct operational clusters have been identified and tracked by Recorded Future's Insikt Group since May 2024, each employing unique brand impersonation lures but sharing a common four-stage kill chain: (1) obfuscated input via encoded/fragmented strings, (2) native execution through trusted system shells, (3) remote ingress from attacker infrastructure, and (4) in-memory execution to minimize forensic artifacts.
Cluster 1 (Intuit QuickBooks, January 2026-present) targets US tax season users with fraudulent QuickBooks verification pages. JavaScript copies obfuscated PowerShell commands to the victim's clipboard, which are then pasted into the Windows Run dialog. The PowerShell stager uses Invoke-RestMethod to contact nobovcs[.]com, downloads a script.ps1 stager, and deploys NetSupport RAT (neservice.exe) via password-protected 7z archives (password: "pppp"). Persistence is achieved through Startup folder shortcuts. The cluster uses distinctive "romantic naming" conventions for staging directories (Heart, Soul, Desire themes) and has recently pivoted to impersonating Zillow real estate services.
Cluster 2 (Booking.com, February 2026-present) uses counterfeit reCAPTCHA v2 challenges targeting travel agency users. The fake CAPTCHA presents identical "bucket" photo selection across all pages. Upon "verification," victims are directed to paste PowerShell commands (-NoProfile -ExecutionPolicy Bypass) that download NetSupport RAT via staging domains bkng-updt[.]com and checkpulses[.]com. C2 infrastructure uses chrm-srv[.]com and ms-scedg[.]com on IP 152.89.244.70.
Cluster 3 (Birdeye, May 2024-present) is the longest-running cluster, spoofing the Birdeye AI marketing platform across 40+ domains incorporating "bird" keywords. Infrastructure tracked via DOM hash pivoting on unique HTML titles and static images. All domains are Cloudflare-hosted. Payload delivery through alababababa[.]cloud, historically associated with Lumma Stealer and RedLine Stealer. JavaScript contains Cyrillic comments documenting PowerShell bypass techniques, suggesting Russian-speaking developers.
Cluster 4 (Dual-Platform Selection, March 2025-present) introduces OS detection to serve tailored lures for Windows and macOS targets. macOS infection chains use multi-stage encoding (hex to Base64 to ZSH execution) with the xxd utility (xxd -r -p) for hex decoding — a rare pattern in legitimate troubleshooting that serves as a high-fidelity behavioral IOC. curl flags (-kfsSL) bypass TLS verification while suppressing errors. The MacSync information stealer is deployed via nohup for background persistence. C2 infrastructure uses octopox[.]com and joeyapple[.]com behind Cloudflare.
Cluster 5 (macOS Storage Cleaning, December 2025-present) targets macOS users with counterfeit system optimization prompts ("Find and remove temporary system files"). Uses similar multi-stage encoded command chains as Cluster 4, deploying payloads in-memory with nohup backgrounding.
The ClickFix methodology has been adopted by nation-state actors including APT28/BlueDelta (Russia) and PurpleBravo (North Korea), elevating it from a purely criminal technique to a state-sponsored initial access vector. The standardized four-stage pattern — obfuscated input, native execution, remote ingress, in-memory execution — represents a significant evolution in social engineering that bypasses endpoint detection by leveraging user trust in system prompts. Recorded Future assesses with high confidence that ClickFix will remain a primary initial access vector throughout 2026, with future iterations expected to incorporate granular browser fingerprinting, conditional payload serving, and increasingly resilient obfuscation.
Target sectors: government, financial, technology, travel, real-estate, marketing, accounting, small-business
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 38 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1566, T1566, T1059, T1059, T1059, T1204, T1204, T1204, T1204, T1027