ClickFix Social-Engineering Technique Becomes Dominant Malware Delivery and Defense-Evasion Vector (CrashFix, FileFix, ConsentFix Variants) — Threadlinqs Intelligence
As of 2026-07-05, ClickFix Social-Engineering Technique Becomes Dominant Malware Delivery and Defense-Evasion Vector (CrashFix, FileFix, ConsentFix Variants) is a high-severity phishing threat attributed to Multiple Threat Actors (KongTuke (Multiple; North Korea (Sapphire Sleet/UNC1069/APT38)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-1127 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Multiple Threat Actors (KongTuke · Multiple; North Korea (Sapphire Sleet/UNC1069/APT38) · FINANCIAL
ClickFix — a social-engineering technique that tricks users into pasting attacker-supplied commands into trusted system dialogs (fake CAPTCHA, browser-crash, or update prompts) — has become the
ClickFix is a social-engineering technique, first observed by Microsoft Threat Intelligence between March and June 2024 in Storm-1607 email campaigns delivering DarkGate malware, that manipulates victims into executing attacker-supplied commands themselves. Rather than exploiting a software vulnerability, ClickFix presents a fake problem — a CAPTCHA/human-verification check, a bogus browser or driver 'update', or (in its 'CrashFix' variant) a deliberately triggered browser crash — and then instructs the victim to 'fix' it by pasting a clipboard-hijacked command into the Windows Run dialog, PowerShell, Windows Terminal, or (on macOS) the Terminal/System Settings authentication prompt. Because the payload is manually typed/pasted and executed by the user via trusted OS dialogs, ClickFix bypasses email attachment scanning, file-based AV signatures, and browser download protections entirely.
By Q2 2026, ReliaQuest's March-May Threat Spotlight found that ClickFix-driven command and file obfuscation accounted for nearly 28% of all observed defense-evasion activity industry-wide, and that ClickFix led initial-access activity via Spearphishing Link (14.9%), making it the single most prevalent initial-access/defense-evasion technique tracked in the quarter. ClickFix's on-host fingerprint (heavy use of mshta.exe, PowerShell, and native LOLBins such as finger.exe) pushed MSHTA-based defense evasion from 16th to 2nd place among tracked defense-evasion techniques, now accounting for roughly a third of that activity.
The technique has evolved well past a one-shot delivery mechanism. Financially motivated initial-access broker KongTuke (aka 404 TDS, Chaya_002, LandUpdate808, TAG-124, Woodgnat) operates the 'CrashFix' sub-variant — a malicious Chrome extension (NexShield, typosquatting uBlock Origin Lite) that deliberately crashes the victim's browser and then serves a fake fix prompt — to deploy the Python-based ModeloRAT RAT and the .NET GateKeeper reconnaissance tool, differentiating payloads for domain-joined corporate targets versus standalone consumer machines. In June 2026, Symantec/Carbon Black linked KongTuke to a new fileless, self-deleting backdoor named Mistic (aka MLTBackdoor), which uses DLL side-loading against a legitimate Microsoft security binary (MpExtMs.exe) to execute entirely in memory. KongTuke has been confirmed as an access broker supplying corporate footholds to six of the most active ransomware operations — Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.
Other threat actors and campaigns observed abusing ClickFix in the same window include: DeepLoad, an AI-obfuscated PowerShell loader that injects into the Windows lock-screen process (LockAppHost.exe) to steal credentials; LeakNet, a ransomware operator that pivoted from IAB-purchased access to running its own ClickFix campaigns via compromised legitimate websites, paired with a Deno-runtime in-memory loader, jli.dll side-loading into Java, PsExec lateral movement, and S3-bucket payload staging; Storm-0249, an IAB that combined ClickFix with DLL side-loading of a trojanized component alongside a legitimate SentinelOne EDR binary to conceal post-exploitation activity; DriveSurge, a new threat actor operating a traffic-distribution system (zTDS) across thousands of compromised legitimate websites to dynamically serve either ClickFix or FakeUpdates lures, including a macOS-specific clipboard-hijacking payload; the Lorem Ipsum loader operators, who pivoted to ClickFix-based delivery via compromised WordPress sites after Microsoft's May 2026 takedown of the Fox Tempest infrastructure and revocation of 1,000+ fraudulent Microsoft Trusted Signing certificates; and North Korea's Sapphire Sleet/UNC1069 (overlapping with APT38/Stardust Chollima/Lazarus Group), which uses ClickFix-style fake technical-interview and video-call lures to deploy a multi-stage macOS malware stack (WAVESHAPER, HYPERCALL, HIDDENCALL, DEEPBREATH, CHROMEPUSH) against cryptocurrency-sector
Target sectors: technology, education, government administration, finance, insurance, professional-services, corporate-enterprise, cryptocurrency
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583.008, T1583.001, T1608.001, T1585.003, T1566.002, T1189, T1204, T1059.001, T1059.003, T1547.001