ClickFix Scam: Users Self-Install Malware via Social Engineering

ClickFix Scam: Users Self-Install Malware via Social Engineering

First seen 8 Sep 2026, 10:33 UTC Facebookwww.proofpoint.com 66.5

Article Content

Browse articles
ThreatCluster

The ClickFix scam has emerged as a significant threat, tricking users into executing malicious PowerShell scripts under the guise of fixing technical issues. Threat actors, including TA571 and the ClearFake activity cluster, utilize social engineering tactics such as fake CAPTCHAs and browser error messages to prompt users to copy and paste harmful commands. This method requires substantial user interaction, making it crucial for individuals to recognize the signs of such scams. The malware delivered through this technique includes DarkGate, Matanbuchus, and various information stealers. Proofpoint researchers first observed this method in March 2024 and have noted its continued use in subsequent campaigns. The technique has been linked to compromised websites that load malicious scripts, leading users to unwittingly install malware. The ongoing campaigns indicate a growing trend in social engineering attacks that exploit user trust and technical confusion.

Key Points: • ClickFix scam uses social engineering to trick users into running malware. • Threat actors TA571 and ClearFake are behind these attacks, employing fake error messages. • Malware includes DarkGate and Matanbuchus, affecting users who follow malicious instructions.

Ask AI about this cluster

Timeline

2024-03-01
First observation of ClickFix technique
Proofpoint researchers noted the ClickFix scam technique being used by TA571 to deliver malware.
Proofpoint
2024-04-01
ClearFake campaign utilizes ClickFix
The ClearFake activity cluster began using the ClickFix technique to deliver malware via compromised websites.
Proofpoint
2024-06-01
Continued use of ClickFix technique
Both TA571 and ClearFake have been observed using the ClickFix method in their campaigns since early June.
Proofpoint