Cybercriminals are constantly evolving their social engineering, with ClickFix being one of the most dangerous and effective forms of attack. It is a methodology that relies on tricking the user into copying and executing malicious code from within the Windows environment — a process that is often disguised as a necessary update or system check.

Realistic Windows Update pages and full-screen tricks
In recent weeks, security researchers have identified new variations of the attack, where attackers display a fake, highly realistic Windows Update animation in full screen. The page appears to “lock” the system, forcing victims to follow specific instructions to supposedly “complete” a critical update.
See also: CISA: Spyware campaigns target Signal & WhatsApp users
Other versions use “human verification”to verify that the user is not a bot. In reality, every command the user types triggers malicious code that has already been automatically copied to the clipboard via JavaScript.
What is ClickFix really?
ClickFix is a social engineering attack that aims to deceive. Instead of trying to exploit a vulnerability in the software, the attacker tries to convince the user to activate the attack. By simply pasting commands into PowerShell or the Windows command line, the system is immediately infected with malware — in this case, the infostealers LummaC2 and Rhadamanthys.
The simplicity and effectiveness of this method have led to the rapid spread of the technique at all levels of cybercrime.

Steganography: Code hidden within images
One of the most striking aspects of the new variant is the use of steganography. The final malicious code is hidden within the pixels of PNG files.
See also: New version of Shai-Hulud worm spreads via npm, GitHub
According to Huntress, the decompression and execution of the payload occurs in multiple stages:
- Using mshta.exe to launch the malicious process.
- Execute PowerShell code that loads Stego Loader.
- Stego Loader reconstructs the encrypted code from within the PNG, using custom C#.
- The final shellcode is run through the Donut, directly in memory, bypassing detection mechanisms.
The complexity and fragmentation of the attack make detection even more difficult.
Avoidance tactics and dynamic deception techniques
Another method observed is the use of “ctrampoline” — a technique where the initial execution point calls thousands of empty functions in order to confuse analyzers and detection tools. The end result is the silent loading of powerful info-stealers.
Recently, following Operation Endgame, part of the Rhadamanthys infrastructure was taken down. However, the Windows Update decoys remain active, although they no longer download the final payload.
See also: Hackers replace the letter 'm' with the combination 'rn' in Microsoft

How users and organizations can protect themselves
Experts give clear instructions for avoiding such attacks:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Disable the Windows Run box where possible
- Monitor suspicious processes, e.g. explorer.exe spawning mshta.exe or PowerShell.
- Check the RunMRU key in the registry for command history.
- Educate users not to execute commands originating from websites.
The ClickFix attacks demonstrate that cybercriminals continue to invest in techniques that rely on user psychology rather than technology alone. Vigilance and awareness are the most important defense tools.
Source: www.bleepingcomputer.com
