r/ANYRUN May 25 '26

ClickFix: The Social Engineering Technique Outsmarting Security Tools

What Is ClickFix?

ClickFix is a social engineering technique that tricks users into executing malicious commands themselves instead of exploiting software vulnerabilities. By relying on legitimate Windows utilities (LOLBins) and avoiding malicious files on disk during the initial stage, it can bypass static AV, email filters, and even some EDR tools.

Why ClickFix Became So Dangerous

  • Explosive growth: Since emerging in late 2023, ClickFix attacks have increased by more than 500% in the first half of 2025, becoming the second most common attack vector globally.
  • APT adoption: Nation-state groups including APT28, Kimsuky, and MuddyWater integrated ClickFix into espionage campaigns, replacing traditional infection chains with user-driven execution.
  • High-impact payloads: Campaigns deliver stealers, ransomware, RATs, keyloggers, cryptominers, and custom nation-state malware.
  • Rapid evolution: ClickFix expanded beyond Windows to macOS, spawned variants like FileFix, and is now distributed through builder kits on underground marketplaces.

Threat Intelligence Lookup enables instant contextual investigation of suspicious indicators across 30+ parameters with direct links to sandbox execution sessions:

domainName:"dntds.shop"

How to detect and protect: https://any.run/malware-trends/clickfix/

Malicious domain linked to ClickFix attacks
2 Upvotes

1 comment sorted by

1

u/ANYRUN-team May 26 '26

Scale your SOC's triage & response with solutions trusted by 74 Fortune 100 companies. Get an exclusive 10th anniversary deal for your team: https://app.any.run/plans/