ClickFix Social Engineering Campaigns Targeting Windows and macOS via Native System Tools

ClickFix Social Engineering Campaigns Targeting Windows and (TL-2026-0282), also tracked as ClickFix, is a high-severity phishing campaign, first published 2026-03-25. It is attributed to APT28 (Russia, North Korea) with high confidence, affects Microsoft Windows, maps to 10 MITRE ATT&CK techniques (T1027, T1059, T1071), and is covered by 9 detection rules and 38 indicators of compromise.

Key facts for TL-2026-0282

Threat ID
TL-2026-0282
Also known as
ClickFix
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-03-25
Last reviewed
2026-03-25
Attribution
APT28
Attribution confidence
HIGH
Nation-state nexus
Russia, North Korea
Motivation
ESPIONAGE
Target sectors
government, financial, technology, travel, real-estate, marketing, accounting, small-business
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
38

Malware and tooling in ClickFix Social Engineering Campaigns Targeting Windows and

Malware and tooling: MacSync, NetSupport RAT

Five distinct ClickFix social engineering clusters identified by Recorded Future Insikt Group, active since May 2024, exploit Windows and macOS by manipulating victims into executing malicious commands via native system tools (PowerShell, zsh, bash). Campaigns impersonate QuickBooks, Booking.com, Birdeye, and macOS system utilities, delivering NetSupport RAT and MacSync stealer. Nation-state groups APT28 (BlueDelta) and PurpleBravo (North Korea) are among operators using this technique.

How ClickFix Social Engineering Campaigns Targeting Windows and works

ClickFix is a rapidly evolving social engineering methodology that bypasses traditional browser-based security controls by shifting exploitation to user-assisted manual execution of obfuscated commands through native system tools. Five distinct operational clusters have been identified and tracked by Recorded Future's Insikt Group since May 2024, each employing unique brand impersonation lures but sharing a common four-stage kill chain: (1) obfuscated input via encoded/fragmented strings, (2) native execution through trusted system shells, (3) remote ingress from attacker infrastructure, and (4) in-memory execution to minimize forensic artifacts.

Cluster 1 (Intuit QuickBooks, January 2026-present) targets US tax season users with fraudulent QuickBooks verification pages. JavaScript copies obfuscated PowerShell commands to the victim's clipboard, which are then pasted into the Windows Run dialog. The PowerShell stager uses Invoke-RestMethod to contact nobovcs[.]com, downloads a script.ps1 stager, and deploys NetSupport RAT (neservice.exe) via password-protected 7z archives (password: "pppp"). Persistence is achieved through Startup folder shortcuts. The cluster uses distinctive "romantic naming" conventions for staging directories (Heart, Soul, Desire themes) and has recently pivoted to impersonating Zillow real estate services.

Cluster 2 (Booking.com, February 2026-present) uses counterfeit reCAPTCHA v2 challenges targeting travel agency users. The fake CAPTCHA presents identical "bucket" photo selection across all pages. Upon "verification," victims are directed to paste PowerShell commands (-NoProfile -ExecutionPolicy Bypass) that download NetSupport RAT via staging domains bkng-updt[.]com and checkpulses[.]com. C2 infrastructure uses chrm-srv[.]com and ms-scedg[.]com on IP 152.89.244.70.

Cluster 3 (Birdeye, May 2024-present) is the longest-running cluster, spoofing the Birdeye AI marketing platform across 40+ domains incorporating "bird" keywords. Infrastructure tracked via DOM hash pivoting on unique HTML titles and static images. All domains are Cloudflare-hosted. Payload delivery through alababababa[.]cloud, historically associated with Lumma Stealer and RedLine Stealer. JavaScript contains Cyrillic comments documenting PowerShell bypass techniques, suggesting Russian-speaking developers.

Cluster 4 (Dual-Platform Selection, March 2025-present) introduces OS detection to serve tailored lures for Windows and macOS targets. macOS infection chains use multi-stage encoding (hex to Base64 to ZSH execution) with the xxd utility (xxd -r -p) for hex decoding — a rare pattern in legitimate troubleshooting that serves as a high-fidelity behavioral IOC. curl flags (-kfsSL) bypass TLS verification while suppressing errors. The MacSync information stealer is deployed via nohup for background persistence. C2 infrastructure uses octopox[.]com and joeyapple[.]com behind Cloudflare.

Cluster 5 (macOS Storage Cleaning, December 2025-present) targets macOS users with counterfeit system optimization prompts ("Find and remove temporary system files"). Uses similar multi-stage encoded command chains as Cluster 4, deploying payloads in-memory with nohup backgrounding.

The ClickFix methodology has been adopted by nation-state actors including APT28/BlueDelta (Russia) and PurpleBravo (North Korea), elevating it from a purely criminal technique to a state-sponsored initial access vector. The standardized four-stage pattern — obfuscated input, native execution, remote ingress, in-memory execution — represents a significant evolution in social engineering that bypasses endpoint detection by leveraging user trust in system prompts. Recorded Future assesses with high confidence that ClickFix will remain a primary initial access vector throughout 2026, with future iterations expected to incorporate granular browser fingerprinting, conditional payload serving, and increasingly resilient obfuscation.

MITRE ATT&CK techniques used in TL-2026-0282

defense-evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

discovery

T1082 System Information Discovery

persistence

T1547 Boot or Logon Autostart Execution

initial-access

T1566 Phishing

Affected products and versions in ClickFix Social Engineering Campaigns Targeting Windows and

  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server 2019; Server 2022
  • Apple — macOS
    Vulnerable versions: Ventura; Sonoma; Sequoia

Remediation for ClickFix Social Engineering Campaigns Targeting Windows and

Immediate actions

  • Block all identified IOC domains and IPs at perimeter firewalls and DNS sinkholes
  • Deploy emergency Splunk/KQL detections for PowerShell Invoke-RestMethod + Invoke-Expression combination
  • Alert SOC teams to monitor for xxd -r -p and nohup curl patterns on macOS endpoints
  • Block AS215439 (PLAY2GO), AS57523 (Chang Way), AS200593 (Prospero), AS41745 (Baykov) at network edge

Workarounds

  • Restrict PowerShell execution policy to AllSigned via GPO
  • Enable System Integrity Protection (SIP) on all macOS endpoints
  • Deploy browser extensions that block clipboard manipulation via JavaScript
  • Implement network-level blocking of password-protected archive downloads

Longer-term hardening

  • Disable Windows Run dialog via Group Policy Objects (GPOs) for non-administrative users
  • Enforce PowerShell Constrained Language Mode (CLM) across all Windows endpoints
  • Deploy AppLocker or Windows Defender Application Control (WDAC) to prevent LOLBin misuse
  • Implement MDM-enforced Terminal restrictions on macOS fleet
  • Conduct targeted social engineering simulations emphasizing manual command execution dangers
  • Deploy EDR with behavioral detection for clipboard-to-execution chains
  • Monitor DOM hashes and page titles for brand impersonation campaigns

Timeline of ClickFix Social Engineering Campaigns Targeting Windows and

  • Cluster 3 (Birdeye) begins operations — first observed ClickFix campaign spoofing Birdeye AI marketing platform across 40+ bird-keyword domains
  • Cluster 4 (Dual-Platform Selection) observed — introduces OS detection to serve tailored Windows/macOS lures and deploys MacSync stealer
  • Cluster 5 (macOS Storage Cleaning) begins operations — targets macOS users with counterfeit system optimization prompts
  • Cluster 1 (Intuit QuickBooks) launches — targets US tax season with fraudulent QuickBooks verification pages delivering NetSupport RAT
  • Cluster 2 (Booking.com) begins operations — uses counterfeit reCAPTCHA v2 challenges to target travel agency users
  • Cluster 4 C2 domains joeyapple[.]com and octopox[.]com first registered and active behind Cloudflare
  • Last observed activity for Cluster 4 C2 domains octopox[.]com and joeyapple[.]com
  • All five ClickFix clusters confirmed actively operating with continued infrastructure expansion and nation-state adoption by APT28 and PurpleBravo
  • Recorded Future Insikt Group publishes comprehensive ClickFix campaign analysis documenting all five clusters with full IOC sets
  • As of 2026-05-29, ClickFix remains a top live initial-access technique: Microsoft (2026-05-06) reported fresh fake-macOS-utility lures dropping MacSync/AMOS infostealers, Malwarebytes flagged 700+ hijacked sites in May, and SmartApeSG/EVALUSION continue dropping NetSupport RAT. No CVE to patch; APT28 and PurpleBravo adoption persists.

Sources cited for ClickFix Social Engineering Campaigns Targeting Windows and

More in phishing

Detection coverage for TL-2026-0282

As of 2026-03-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0282 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats