{"id":11513,"date":"2025-07-14T12:53:25","date_gmt":"2025-07-14T05:53:25","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=11513"},"modified":"2026-06-25T10:01:44","modified_gmt":"2026-06-25T03:01:44","slug":"clickfix-enables-hackers-to-take-control-of-computers-with-a-simple-paste","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/en\/2025\/07\/14\/clickfix-enables-hackers-to-take-control-of-computers-with-a-simple-paste\/","title":{"rendered":"&#8220;ClickFix&#8221; enables hackers to take control of computers with a simple paste."},"content":{"rendered":"<p><b>ClickFix \u2013 phishing is expected to explode in cyberattack campaigns in 2025. Unlike traditional attacks via scam emails or malicious attachments, this tactic uses the &#8220;fast fix&#8221; mentality to get users to run their own malicious commands. <\/b><\/p>\n<div style=\"text-align: center\"><a class=\"js-lbImage\" style=\"cursor: pointer\" href=\"https:\/\/whitehat.vn\/attachments\/1752477958423-png.17303\/\" target=\"_blank\" rel=\"noopener\" data-caption=\"&lt;h4&gt;1752477958423.png&lt;\/h4&gt;&lt;p&gt;&lt;a href=&quot;https:&amp;#x2F;&amp;#x2F;whitehat.vn&amp;#x2F;threads&amp;#x2F;chieu-thuc-clickfix-giup-tin-tac-chiem-quyen-kiem-soat-may-tinh-chi-bang-mot-cu-dan-lenh.18558&amp;#x2F;#post-44065&quot; class=&quot;js-lightboxCloser&quot;&gt;WhiteHat Team \u00b7 14&amp;#x2F;07&amp;#x2F;2025 l\u00fac 2:36 PM&lt;\/a&gt;&lt;\/p&gt;\" data-fancybox=\"lb-thread-18558\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1752477958423.png\" src=\"https:\/\/whitehat.vn\/data\/attachments\/17\/17638-572f8eff2d8efe1213880e6cb10a1345.jpg\" alt=\"1752477958423.png\" width=\"854\" height=\"400\" \/><\/a>\u200b<\/div>\n<p>ClickFix is a social engineering hack in which bad guys impersonate technicians or major tech brands such as DocuSign, Okta, providing &#8220;debug instructions&#8221; for common problems such as driver errors, annoying pop &#8211; ups, or login errors. As a result, hackers can take control of computers, steal data, and even pave the way for ransomware attacks.<\/p>\n<p>But instead of correcting the actual error, this tutorial requires the user to copy-paste a command fragment (usually PowerShell) into the Run box (Win+R) or terminal window (Wins+X) on Windows. This command is pre-installed in the clipboard via malicious JavaScript code from fake websites, malicious ads, fake tutorial videos, or &#8220;pseudo&#8221; technical support forums &#8211; a technique also known as pastejacking.<\/p>\n<p>The danger is that there are no malicious attachments, no deceptive links, and it&#8217;s the user who runs the malicious code without knowing it.<\/p>\n<p>In 2025, attack groups have incorporated ClickFix into multiple campaigns spreading spyware and malicious code that hijack remote control, including:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">NetSupport RAT: Takes advantage of fake DocuSign and Okta interfaces, luring users to paste PowerShell instructions. The scenario hit the health, legal, telecom, and mining sectors in May 2025.<\/li>\n<li data-xf-list-type=\"ul\">Latrodectus Malware: Distributed via ClearFake-encoded websites, using side-loading DLLs to install malicious code.<\/li>\n<li data-xf-list-type=\"ul\">Lumma Stealer: Targeted IT, automotive, energy sectors with malicious MSHTA commands and domain names forged log IP services.<\/li>\n<\/ul>\n<p>ClickFix&#8217;s effects are dangerous and difficult to detect:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">The user is hijacked (via Remote Access Trojan).<\/li>\n<li data-xf-list-type=\"ul\">Stolen data and accounts, including emails, passwords, internal documents.<\/li>\n<li data-xf-list-type=\"ul\">Paves the way for ransomware or other malicious code to spread.<\/li>\n<li data-xf-list-type=\"ul\">The industries affected span the spectrum: high technology, banking, manufacturing, retailing, government, utilities, etc..<\/li>\n<\/ul>\n<p>This tactic also poses significant difficulties for traditional security systems because:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">No unknown files initially downloaded.<\/li>\n<li data-xf-list-type=\"ul\">No fraudulent email links.<\/li>\n<li data-xf-list-type=\"ul\">The code run is done by the user himself.<\/li>\n<\/ul>\n<p>However, forensics traces are still detectable, such as unusual commands in Windows RunMRU or PowerShell sessions that are initiated after clipboard paste.<\/p>\n<p>Universal users are the goal of ClickFix, thus raising awareness is a top priority. Signs to watch for:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">The site asks for &#8220;paste the command to correct the error.&#8221;<\/li>\n<li data-xf-list-type=\"ul\">Unknown technical instructions on unorthodox video\/forum.<\/li>\n<li data-xf-list-type=\"ul\">Warning from Windows requesting administrator privileges after pasting command.<\/li>\n<\/ul>\n<p>To minimize the risk of ClickFix attacks, WhiteHat recommends that organizations and users take the following measures:<\/p>\n<ol>\n<li data-xf-list-type=\"ol\">Keep software and operating systems up to date<br \/>\nFully install security patches to seal known vulnerabilities that hackers can exploit.<\/li>\n<li data-xf-list-type=\"ol\">Use trusted security software<br \/>\nImplement antivirus software, firewalls and end protection tools to detect and stop malicious code.<\/li>\n<li data-xf-list-type=\"ol\">Be absolutely alert for &#8220;paste and running&#8221; commands from unknown sources<br \/>\nDon&#8217;t follow any instructions that require you to copy-paste commands to Run (Win+R) or PowerShell\/Terminal (win+X ), whether they look legitimate or come from a familiar brand.<\/li>\n<li data-xf-list-type=\"ol\">Security Awareness Training for Employees<br \/>\nOrganize periodic training courses to help users identify ClickFix tricks and other sophisticated forms of fraud.<\/li>\n<li data-xf-list-type=\"ol\">Monitoring abnormal system behavior\n<ul>\n<li data-xf-list-type=\"ul\">Monitor the clipboard for malicious sticky bits.<\/li>\n<li data-xf-list-type=\"ul\">Record and analyze unusual PowerShell sessions.<\/li>\n<li data-xf-list-type=\"ul\">Check the RunMRU entry in the Windows registry, which saves commands that have been run through the Run window.<\/li>\n<\/ul>\n<\/li>\n<li data-xf-list-type=\"ol\">Use of advanced security tools\n<ul>\n<li data-xf-list-type=\"ul\">Palo Alto Networks: Advanced WildFire, URL Filtering, DNS Security.<\/li>\n<li data-xf-list-type=\"ul\">Cortex XDR: Automatic behavioral monitoring and response to suspicious activity.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>ClickFix is a good example of an attacker who does not need high &#8211; tech tools, just a user&#8217;s psychological gullibility and lack of vigilance. In the context of increasingly sophisticated and &#8220;friendly&#8221; attack techniques, organizations and individual users cannot simply rely on antivirus software. The solution lies in vigilance, basic cybersecurity education, and an intelligent surveillance system.<\/p>\n<div style=\"text-align: right\"><b><i>According to WhiteHat, Cyber Press<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/chieu-thuc-clickfix-giup-tin-tac-chiem-quyen-kiem-soat-may-tinh-chi-bang-mot-cu-dan-lenh.18558\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/chieu-thuc-clickfix-giup-tin-tac-chiem-quyen-kiem-soat-may-tinh-chi-bang-mot-cu-dan-lenh.18558\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>ClickFix \u2013 phishing is expected to explode in cyberattack campaigns in 2025. Unlike traditional attacks via scam emails or malicious attachments, this tactic uses the &#8220;fast fix&#8221; mentality to get users to run their own malicious commands. \u200b ClickFix is a social engineering hack in which bad guys impersonate technicians or major tech brands such [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[351],"tags":[],"class_list":["post-11513","post","type-post","status-publish","format-standard","hentry","category-news-announcements"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11513","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=11513"}],"version-history":[{"count":1,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11513\/revisions"}],"predecessor-version":[{"id":11514,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11513\/revisions\/11514"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=11513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=11513"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=11513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}