ClickFix moves into the browser and onto WebDAV, Cisco Talos finds
Cisco Systems Inc.’s Talos Threat Intelligence group today detailed two ClickFix campaigns that push the technique past the copy-and-paste PowerShell prompt it is known for, one that never touches the operating system at all and one that ends in a stealer plus whichever follow-on payload the operators choose to task.
ClickFix emerged in 2024 and has become known for one move: a page claiming some check has failed and offering a command for the visitor to paste into the Windows Run dialog or a Mac terminal. Having the target run the code sidesteps the download warnings and email filtering that catch attachments. The technique has spread quickly since, turning up last month in a fake OpenAI Codex installer aimed at Mac users that Cato Networks Ltd. documented.
In the first of the campaigns Talos detailed, the target is never asked to run anything against Windows. The lure walks the victim through pasting JavaScript into the Chrome address bar, or in a later version installing it into the Tampermonkey browser extension, which reloads the code on every visit to the targeted site.
What the code does is skim. It hooks the browser’s fetch application programming interface, replaces cryptocurrency deposit addresses in server responses and in the clipboard, and renders counterfeit “bonus” elements into the page to account for the numbers the victim is seeing. Talos observed the campaign against swap service SwapZone.io and later the trading aggregator SimpleSwap.io.









