The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
August 31, 2026
An emerging ClickFix-style campaign tricks users into opening PowerShell and executing a malicious command, kicking off a complex attack chain designed to establish a foothold inside enterprise networks.
Threat actors in recent years have increasingly relied on ClickFix for social engineering campaigns. Generally, a user visits a compromised or attacker-controlled website, only to be told they need to paste a command into Windows Run or MacOS's Terminal. The command usually connects to an attacker-controlled server, which typically downloads and installs infostealers or other types of malware.
The reason it's called ClickFix is that the victim is typically presented with instructions to "fix" a problem, complete a verification step, or troubleshoot a browser issue by running a command supplied by the attacker. One variant sees the attacker drawing potential victims into a fake Zoom call through a browser; technical problems arise with sound or video, and victims are told they must paste a command to fix the issue.










