Full Report
ClickFix attacks leave no file to scan or block, which is why most endpoint tools miss it. See how Huntress Attack Disruption kills the chain in under a second.
Analysis Summary
# Tool/Technique: ClickFix (Social Engineering Delivery Mechanism)
## Overview
ClickFix is a sophisticated social engineering technique that bypasses traditional file-based endpoint security by convincing users to execute malicious commands manually. Instead of relying on email attachments or software exploits, it presents victims with a fake "CAPTCHA" or "fix" page that instructs them to use keyboard shortcuts (Windows+R) to paste and execute a malicious "cradle" script directly into the system's Run dialog.
## Technical Details
- **Type:** Technique / Delivery Mechanism
- **Platform:** Windows (primarily, via PowerShell and Command Prompt)
- **Capabilities:** Fileless execution, bypasses signature-based detection, rapid multi-stage payload delivery.
- **First Seen:** Early 2024 (increasing in prevalence through late 2024)
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- **T1566.002 - Phishing: Spearphishing Link** (Directing users to fake CAPTCHA sites)
- **TA0002 - Execution**
- **T1204.002 - User Execution: Malicious File** (Executing the pasted command)
- **T1059.001 - Command and Scripting Interpreter: PowerShell**
- **TA0005 - Defense Evasion**
- **T1027 - Obfuscated Files or Information**
- **T1218 - System Binary Proxy Execution** (Using `powershell.exe` or `cmd.exe` via `Run` dialog)
## Functionality
### Core Capabilities
- **Social Engineering:** Displays high-fidelity fake error messages or CAPTCHA prompts (e.g., "Verification failed, please press Win+R and paste the fix").
- **Clipboard Abuse:** Leverages the user's clipboard to transport the malicious command, leaving no browser-based "download" trail.
- **Fileless Injection:** Executes a small "cradle" script that exists only in memory or as a command-line argument to fetch subsequent stages.
### Advanced Features
- **Anti-Sandboxing:** Because the execution requires specific manual user interaction (Win+R, Ctrl+V, Enter), automated sandboxes often fail to trigger the malicious behavior.
- **Rapid Staging:** Moves from initial execution to secondary payload (e.g., info-stealers or RATs) in under a few seconds.
## Indicators of Compromise
- **File Hashes:** Typically N/A for Stage 1 (Fileless).
- **File Names:** Often involves legitimate binaries like `powershell.exe`, `cmd.exe`, or `mshta.exe`.
- **Registry Keys:** May modify `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU` (tracking recently used Run commands).
- **Network Indicators:**
- `hxxps[:]//lurchmath[.]com/` (Example staging/decoy domain)
- `hxxps[:]//pastebin[.]com/raw/...` (Common for raw script hosting)
- **Behavioral Indicators:**
- `explorer.exe` spawning `powershell.exe` with long, base64-encoded command strings.
- PowerShell commands containing `Invoke-Expression` (IEX) or `WebClient.DownloadString`.
## Associated Threat Actors
- **ClearFake**
- **TA571**
- **Various Info-stealer operators** (Luminex, Vidar, StealC)
## Detection Methods
- **Behavioral Detection:** Monitor for the specific process parent-child relationship of `explorer.exe` → `powershell.exe` where the command line contains suspicious download cradles.
- **Telemetry Analysis:** Detection of `Win+R` usage followed immediately by network activity from a shell interpreter.
- **Memory Scanning:** Scanning for injected code or anomalous PowerShell scripts residing in memory.
## Mitigation Strategies
- **User Education:** Train users to never paste and run commands provided by websites, regardless of how "official" the CAPTCHA looks.
- **Attack Surface Reduction (ASR):** Implement ASR rules to "Block executable content from email client and webmail" and "Block process creations originating from RPC commands."
- **Restricting PowerShell:** Enforce Constrained Language Mode or restrict PowerShell execution to signed scripts via Execution Policy.
## Related Tools/Techniques
- **Browser-in-the-Browser (BitB):** A similar social engineering tactic using fake login windows.
- **HTML Smuggling:** Another technique used to bypass perimeter security by "building" a file on the client side.
- **PowerShell Cradles:** The underlying execution method used once the script is pasted.