ClickFix / KongTuke Clipboard-Hijacking Social-Engineering Technique (MITRE T1204.004) — Fake-CAPTCHA Lures Delivering Infostealers, RATs, and Ransomware — Threadlinqs Intelligence
As of 2026-07-05, ClickFix / KongTuke Clipboard-Hijacking Social-Engineering Technique (MITRE T1204.004) — Fake-CAPTCHA Lures Delivering Infostealers, RATs, and Ransomware is a high-severity threat intel threat attributed to KongTuke (compromised-WordPress ClickFix, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1130 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: KongTuke (compromised-WordPress ClickFix · FINANCIAL
Independent verification of IOCs cited in a Tier-1 SOC triage methodology article (cybersecuritynews.com) found that the example domain dntds.shop and associated IP 89.190.158.132 are genuinely
The originating source article (cybersecuritynews.com, sponsored by ANY.RUN) is a general Tier-1 SOC alert-triage methodology piece that uses three example indicators — IP 107.170.45.91 and domains dntds.shop and fourdigs.cyou — purely to illustrate an IOC-enrichment workflow, with no campaign attribution given in-article. The HUNT phase correctly flagged this as containing no reportable threat on its face. However, RESEARCH-phase independent pivoting on the cited indicators found that one of them, dntds.shop, is NOT merely illustrative: it is an actively tracked malicious domain. ANY.RUN interactive sandbox analysis rendered a 'malicious activity' verdict against dntds.shop across at least two independent submissions, ThreatFox (abuse.ch, IOC #1780849) tags it 'clickfix' and 'phishing', Gridinsoft assigns it a 1/100 trust score with 19 blacklist detections and phishing-signal flags, and urlscan.io holds a recorded scan of the domain. ANY.RUN's own May-2026 technical write-up on the ClickFix technique separately documents 89.190.158.132 as a destination IP observed during ClickFix sandbox detonations, corroborating that this infrastructure participates in the live ClickFix ecosystem rather than being a random illustrative artifact. The other two indicators from the source article — fourdigs.cyou and 107.170.45.91 — could NOT be independently corroborated as malicious via WebSearch, ThreatFox, or reputation-service lookups at the time of this research; they are retained below as low-confidence/unconfirmed IOCs for completeness and future re-checking, and are NOT treated as confirmed threat infrastructure.
ClickFix (aka 'paste-and-run', 'fake-CAPTCHA', formally MITRE ATT&CK sub-technique T1204.004 'User Execution: Malicious Copy and Paste', added to Enterprise ATT&CK in March 2025) is a clipboard-hijacking social-engineering technique first documented in the wild in March 2024 and now one of the most prevalent initial-execution vectors tracked by the industry (Huntress reported a 631% increase in ClickFix-related incidents between August 2024 and August 2025). Victims land on a page (via phishing link/attachment, malvertising, SEO poisoning, or a compromised legitimate website) that displays a fake reCAPTCHA/Cloudflare Turnstile check, a fake Windows/browser error, or a fake 'verify you are human' prompt. JavaScript on the page silently writes an obfuscated command to the clipboard via the clipboard API; the victim is instructed to press Win+R (or open PowerShell/Terminal on macOS), paste (Ctrl+V), and press Enter, personally executing the attacker's first-stage payload. First-stage payloads are typically short PowerShell one-liners, mshta.exe/rundll32.exe/msbuild.exe/regasm.exe LOLBin invocations, or curl/wget downloaders that retrieve an obfuscated second-stage script, which in turn fetches the final payload — commonly infostealers (Lumma Stealer/LummaC2, Atomic macOS Stealer), loaders (DarkGate, Latrodectus, MintsLoader, Emmenhtal), RATs (AsyncRAT, NetSupport RAT, SectopRAT, Xworm, Quasar RAT, Interlock RAT, modeloRAT), or, via affiliate hand-off, ransomware (Epsilon Red; and via the KongTuke cluster, Rhysida, Interlock, 8Base, Akira, and AlphV/BlackCat).
A distinct, separately-documented ClickFix delivery cluster tracked by Trend Micro under the name 'KongTuke' compromises WordPress sites at scale (300+ sites and 40+ traffic-distribution-system domains observed), injecting malicious JavaScript (e.g., served from foodgefy.com / 162.33.178.171) that redirects visitors into fake-CAPTCHA ClickFix pages. KongTuke's chain has been observed delivering the Python-based modeloRAT and ultimately handing off infected hosts to multiple ransomware affiliate groups. Domains nitzschi.com and windlrr.com are separately tagged to the KongTuke cluster on ThreatFox. ClickFix has also been weaponized by nation-state actors independent of KongTuke or the dntds.shop cluster: Group-IB documents APT28 using ClickFix against Ukrainian government t
Target sectors: education, technology, government administration, health, finance
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1583, T1584, T1608, T1608, T1566, T1566, T1189, T1204, T1204, T1059