FileFix: The New Social Engineering Attack Building on ClickFix Tested in the Wild
Score: 76/100
4 articles
100.0% coherence
1 day ago
Activity Timeline
Fix the Click: Preventing the ClickFix Attack Vect...
Palo Alto Unit 42
Jul 10
10:00
KongTuke Attacking Windows Users With New Interloc...
Cybersecurity News
Jul 14
13:34
Interlock ransomware adopts FileFix method to deli...
BleepingComputer
Jul 14
18:36
FileFix: The New Social Engineering Attack Buildin...
Check Point Blog
Primary Article
Jul 16
13:00
Primary Article
Check Point Blog 6 hours ago
Check Point Research identifies how the new social engineering technique, FileFix, is being actively tested by threat actors in the wild.
Attackers have long exploited human trust as a primary attack surface, and they’re doing it again with a new technique called FileFix.
FileFix is a recently uncoveredsocial engineering attackthat builds on the widely abused ClickFix tactic. Unlike ClickFix, which tricks users into running malicious commands via the Windows Run dialog, FileFix takes a subtler approach: it opens a legitimate Windows File Explorer window from a webpage and silently loads a disguised PowerShell command into the user’s clipboard. When the victim pastes into the Explorer address bar, the malicious command executes. This attack relies not on software vulnerabilities but on exploiting routine user actions and trust. Within just two weeks of FileFix’s public disclosure, Check Point Research observed this technique being actively tested in the wild by a known threat actor. Thi...
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Unlock AI Insights
Get AI-generated executive, technical, and remediation briefs with Pro.
Interlock ransomware adopts FileFix method to deliver malware
Bill Toulas
July 14, 2025
02:36 PM
0
Hackers have adopted the new technique called 'FileFix' in Interlock ransomware attacks to drop a rem...
Threat Research Center
Threat Research
Malware
Fix the Click: Preventing the ClickFix Attack Vector
By:Rem DudasNoa Dekel
Rem Dudas
Noa Dekel
Published:July 10, 2025
Categories:MalwareThreat Research
...
A sophisticated malware campaign leveraging the KongTuke threat cluster has emerged, targeting Windows users through a novel FileFix technique that deploys an advanced PHP-based variant of the Interlo...
Save to Folder
Choose a folder to save this cluster:
We use cookies
We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.
Cookie Settings
Essential Cookies
Required for the website to function. Cannot be disabled.
Session management and authentication
Security and fraud prevention
Cookie consent preferences
Analytics Cookies
Help us understand how visitors interact with our website.