Cybercriminals continue to evolve their tactics, shifting their focus from traditional phishing scams to more targeted social engineering attacks. Throughout 2025, threat actors adopted the ClickFix, using fake pages to trick users into running PowerShell commandsthat install NetSupport Manager, a legitimate remote administration tool that is now being used by hackers to gain unauthorized access.

Multi-stage infection chain
The attack begins with deceptive ClickFix pages, which ask the victim to execute commands. Once the command is executed, a multi-stage infection process: PowerShell-based loaders download encoded JSON blobs from attacker-controlled servers, decode the payloads, and install NetSupport on the system. eSentire have identified at least three independent groups using this method, confirming that the technique has been widely adopted.
See also: Hackers target sites through outdated WordPress plugins
Hiding and persistence techniques
Loaders use multi-layered concealment techniques:
- Base64 encoding for JSON blobs.
- Installing secondary loaders via MSI packages executed with msiexec.
- Create hidden folders and shortcuts in
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup. - Delete RunMRU to make analysis more difficult.
This level of operational security increases the success rates of attacks and reduces the chances of detection by static security mechanisms.

The risks for businesses
ClickFix attacks don't just target a user's computer. Attackers gain remote control, maintain persistence, and can:
- Check and modify critical files.
- Execute commands on corporate networks.
- They steal sensitive data.
- Install further malware.
Exploiting the human factor makes attacks particularly effective, as employees follow misleading instructions to solve seemingly "technical problems."
See also: Hackers steal Discord accounts via RedTiger

Protection measures
Organizations must implement technical and organizational measures:
- Whitelist applications to restrict MSI and PowerShell execution.
- Monitoring for base64 decoding, flags like
-nopand-ep Bypass, and non-standard msiexec executions. - Continuous monitoring of logs and SIEM rules for chained executions and abnormal network traffic.
Safety training and culture
User training remains critical. Employees must:
- They avoid executing commands from unverified pages.
- They recognize suspicious ClickFix prompts.
- They immediately contact IT departments in suspicious incidents.
Incident handling
In case of infection:
- Isolate affected systems immediately.
- Perform a full analysis.
- Implement incident response playbooks.
- Report incidents to authorities and work with cloud providers to restrict C2 servers.
See also: New phishing campaign targets LastPass users
The new reality of cybercrime
The ClickFix attacks demonstrate that criminals are organized and exploiting legitimate tools for malicious purposes. Protection requires a combination of technology, education, and information sharing. Continuous monitoring, strict policy enforcement, and red team exercises drastically reduce the risk of these sophisticated attacks succeeding.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
