ClickFix Malware Evolves with Multi
The ClickFix malware now uses videos, timers, and OS-specific tricks to deceive users into infecting their own devices.
Cybercriminals continue to refine social engineering techniques, and the latest evolution of the ClickFix malware campaign demonstrates how far deception has advanced.
According to researchers at Push Security, new variants of ClickFix attacks now feature video tutorials, countdown timers, and automatic operating system detection, all designed to trick users into infecting their own systems.
ClickFix attacks have been active for several years, typically relying on a simple yet highly effective social engineering tactic: convincing victims to paste and execute malicious code on their own devices.
The new campaign maintains that same core method but has added multiple layers of sophistication to increase success rates.
Traditionally, ClickFix pages displayed text instructions claiming to verify a user’s identity or fix a supposed software issue.
Victims were told to copy code from a webpage and run it in their terminal or command prompt — actions that would silently download and execute malware.
However, recent campaigns identified by Push Security researchers replace these static instructions with embedded video tutorials that walk users through the process of running the malicious code.
The inclusion of video makes the attack feel more authentic and interactive, lowering skepticism and reducing the chance of user error.
The new ClickFix webpages resemble Cloudflare CAPTCHA verification screens, complete with realistic logos, design elements, and interactive elements.
Behind the scenes, JavaScript scripts automatically detect the victim’s operating system — Windows, macOS, or Linux — and adjust the malicious commands accordingly.
Once a user lands on the page, the fake verification screen begins a one-minute countdown timer, adding psychological pressure and urgency.
Users are told they must complete the verification within the time limit to continue accessing the website.
A “users verified in the last hour” counter further reinforces the illusion of legitimacy by implying that others have completed the same process safely.
Push Security reports that the malicious JavaScript can also automatically copy commands to the clipboard, allowing users to paste and execute the payload without ever seeing the actual code.
This automation minimizes the likelihood of mistakes that could alert the victim.
Earlier versions of ClickFix were already known to target all major operating systems, but the new campaigns introduce dynamic instruction delivery that tailors payloads to each environment.
For Windows users, ClickFix often employs MSHTA or PowerShell scripts, leveraging built-in Windows components to fetch and execute the payload.
On macOS and Linux, attackers rely on shell commands and living-off-the-land binaries that do not trigger standard antivirus or endpoint detection alerts.
Push Security notes that many of these malicious pages are distributed through malvertising on Google , where attackers purchase ads or use SEO poisoning to push infected sites higher in results.
Some actors also compromise legitimate websites through vulnerable WordPress plugins , injecting their JavaScript payloads directly into trusted pages.
Researchers warn that future versions of ClickFix may run entirely in the browser, allowing malicious code execution without requiring the victim to open a terminal.
This browser-based evolution would make detection even harder, as endpoint detection and response (EDR) tools typically focus on monitoring system-level processes, not in-browser activity.
The payloads associated with ClickFix attacks vary, but information-stealing malware remains the most common.
These infostealers are designed to collect browser credentials, cryptocurrency wallet data, and system information, which can then be sold on dark web marketplaces or used for follow-up attacks.
Defending against ClickFix requires both technical controls and user awareness, as the attack primarily relies on social engineering rather than just software vulnerabilities. Key mitigations include:
These mitigations can help build cyber resilience against ClickFix attacks.
ClickFix’s success lies not just in sophisticated malware, but in manipulating human behavior.
This growing ability to exploit human trust reinforces why adopting zero-trust principles is essential to counter emerging threats.
Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.
Researchers found nine NuGet packages hiding time-delayed code that can crash apps or corrupt industrial systems.
Cybercriminals are exploiting hotel booking platforms in a global phishing scheme that tricks guests into paying for reservations twice.
Cisco warns that hackers are actively exploiting a 0-day flaw in its firewall software, putting unpatched systems at risk of full compromise.
The CBO breach exposes how the government shutdown is weakening federal cybersecurity defenses when they’re needed most.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
