SOCLIFE
SOCLIFE

Evidence-led security analysis

Published knowledge

Search SOC//LIFE

ThreatsTHREAT-002

Threat report

ClickFix in 2026: From Fake Fixes to Remote Access

2026 reporting shows ClickFix evolving across fake fixes, RAT delivery, credential theft, and hands-on-keyboard intrusion activity.

Public research

Reported facts and defensive takeaways are labeled separately.

Reviewed

Public reporting

What happened

ClickFix remained a fast-moving social-engineering technique in 2026 because attackers could change the lure, payload, and infrastructure while preserving the same core action: convince the user to execute attacker-supplied code. Public reporting documented distinct RAT, stealer, browser-disruption, and hands-on-keyboard outcomes rather than one universal chain.

Why SOC teams should care

The user can become the execution mechanism, native tools can blend with legitimate administration, and one foothold can progress into credential theft, remote access, or lateral movement. ESET reported a 108% increase in ClickFix detections between H2 2025 and H1 2026, reinforcing the need to correlate arrival, endpoint, and network behavior.

Public reporting

How the attack worked

  1. Initial Access01

    A lure reaches the user

    Public reporting describes phishing, malicious advertising, compromised websites, and harmful browser extensions as different arrival paths.

    Useful logs: Network, Dns, Endpoint

  2. Initial Access02

    A fake verification or repair prompt appears

    The lure asks the user to perform a verification or repair action. CrashFix added deliberate browser disruption before presenting the fake warning.

    Useful logs: Endpoint, Network

  3. Execution03

    The user executes attacker-supplied code

    The core ClickFix action moves execution through Windows Run, a shell, a terminal, or another user-driven path.

    Useful logs: Registry, Process

Defensive takeaways

Behavior to watch

Logs that help

Registry

RunMRU and startup locations connect the user-driven command with later persistence.

  • Suspicious RunMRU values containing native tools, URLs, or retrieval commands.
  • New Run keys or security-control values after the initial execution.

Process

Process parentage and command lines show how a browser or user action became native-tool retrieval and execution.

  • Pcalua, MSHTA, rundll32, PowerShell, Python, curl, certutil, or msiexec in an unusual user-driven chain.
  • Defender changes, tunneling, or remote-execution commands after the foothold.

Network

Web, proxy, DNS, and endpoint connections preserve arrival context, remote retrieval, C2, and wider exposure.

  • A recovered patient-zero URL or referrer reached by additional users or devices.
  • Source-scoped infrastructure followed by matching execution or persistence.

File

File names, paths, hashes, and initiating processes connect retrieval with loader, stealer, or RAT execution.

  • HTA, MSI, DLL, script, or executable creation after the user-driven command.
  • A source-reported hash written or executed on another endpoint.

Endpoint

Endpoint context brings together browser access, credential activity, security-control state, tunnels, remote execution, and persistence.

  • Browser credential or cookie access after the delivery chain.
  • New remote-control tooling, Defender impairment, or lateral-movement behavior.

Defensive takeaways

How to detect this behavior

Correlate suspicious Run activity with follow-on execution

Correlate a suspicious RunMRU command with same-device native-tool execution that retrieves remote content or silently launches a package inside a short window.

Logs needed

  • RunMRU registry events with device, user, command, and timestamp.
  • Process creation with image, command line, parent context, device, user, and timestamp.
  • Optional network and file enrichment for destinations and retrieved artifacts.

Raise confidence with persistence or post-compromise behavior

Add weight when the same device creates startup persistence, contacts new infrastructure, accesses browser data, impairs security controls, creates a tunnel, or begins remote execution.

Logs needed

  • Registry, file, network, endpoint, authentication, and remote-administration telemetry.
  • Environment-specific definitions of approved persistence, security-control, and remote-management activity.
View detection

Defensive takeaways

How to hunt this behavior

Recover and pivot the patient-zero arrival path

Derive the Run time from endpoint telemetry, recover the preceding URL or referrer where retained, and search it across users and devices before expanding through source-scoped infrastructure.

What would weaken it

  • The recovered web activity is unrelated to the Run event or appears only on patient zero without matching endpoint behavior elsewhere.
  • No arrival URL or referrer is retained, and source-reported infrastructure produces no matching execution or persistence.

Expand from infrastructure into post-compromise behavior

Search RunMRU, native-tool execution, silent packages, Run keys, credential access, Defender changes, tunnels, and remote execution so infrastructure rotation does not end the hunt.

What would weaken it

  • An approved workflow explains the exact command, destination, owner, scope, and change window.
  • Persistence and remote-administration activity predates the candidate or resolves to independently approved work.
View threat hunt

Public reporting

Indicators reported by the source

Values are defanged and are not live links.
Indicators reported in the Huntress May 2026 intrusion.13 values
  • Domaincl[.]distritovagas[.]com
  • Domainsonra[.]eutialyson[.]com
  • Domainanus-staylard[.]xyz
  • Domainresumeacceptable[.]com
  • Ip77[.]110[.]122[.]58
  • Ip213[.]165[.]41[.]26
  • FilenameRunSearch.exe
  • Hash2abe5dd3a057fdef935722e50e9251c272d29fd26113187b853a1f9a9cb89d9b
  • Filenameinst24.msi
  • Hash79f7b67ce8b39070f3e1c2b90fce0ce84134782a7dedcccc1edac197ee9e089b
  • Filenameavast_update.bin
  • Hash3b7ae925e2d64522b4f69b56285b05aeca8c5aab5ab46a9c02c4fafb69d881ce
  • Other0xb3f2897f2bc797e5b9033faef8c81e92b01cb831
Indicators reported in the Huntress February 2026 intrusion.7 values
  • Urlhttp[:]//binclloudapp[.]com/466943
  • Urlhttps[:]//marle[.]io/check/updprofile[.]aspx
  • Domainwww[.]ndibstersoft[.]com
  • FilenameSystemStatus.dll
  • Hash6ffae128e0dbf14c00e35d9ca17c9d6c81743d1fc5f8dd4272a03c66ecc1ad1f
  • FilenameBeacon.exe
  • Hasheecc83add16f3d513a9701e9a646b1885014229ac6f86addd6b10afb64d1d2af
Indicators reported in Microsoft's January and February 2026 CrashFix research.10 values
  • Domainnexsnield[.]com
  • Ip69[.]67[.]173[.]30
  • Ip144[.]31[.]221[.]197
  • Ip158[.]247[.]252[.]178
  • Ip170[.]168[.]103[.]208
  • Hashc46af9ae6ab0e7567573dbc950a8ffbe30ea848fac90cd15860045fe7640199c
  • Filenamect.exe
  • Hashbeb0229043741a7c7bfbb4f39d00f583e37ea378d11ed3302d0a2bc30f267006
  • Filenamescript.ps1
  • Hashc76c0146407069fd4c271d6e1e03448c481f0970ddbe7042b31f552e37b55817
Indicators reported by Microsoft in ACR Stealer campaigns observed from late April to mid-June 2026.16 values
  • Domainlooksta[.]icu
  • Domaincontrite[.]quirksturdy[.]icu
  • Domainux[.]strainedeasily[.]icu
  • Domaincpppemwjewjoiwejow[.]sale
  • Domainbreaksd[.]wifihot[.]icu
  • Domainwalter[.]filloco[.]icu
  • Domainfast[.]raidher[.]icu
  • Domainapigrokcloud[.]icu
  • Domainenhanceblabber[.]cc
  • Domaindeep-harborio[.]com
  • Domainauramatrixa[.]com
  • Domainzealpraxis[.]com
  • Domainprism-vertex[.]com
  • Domainprism-matrixs[.]com
  • Domainproton-network[.]com
  • Domaincreativecommunityinfo[.]art

Review record

Sources and limitations

Reviewed
Reported window
January 2026 July 2026

Observation basis

The approved source set covers Microsoft's January and February CrashFix observations, Huntress intrusions reported in February and May, ACR Stealer activity observed from late April to mid-June, and Microsoft's July publication. It does not claim continuous activity or one shared campaign.

Confidence in this conclusion

Multiple first-party investigations and vendor reports independently document the stable user-driven execution pattern and materially different 2026 payload chains. Confidence remains bounded to the cited reporting; ClickFix is not attributed to one actor, and no single payload, infrastructure set, or follow-on behavior is universal.

Limitations

  • ClickFix is a technique used across different activity sets and is not attributed here to one actor.
  • The cited 2026 examples use different lures, delivery chains, payloads, infrastructure, and follow-on behavior; they are not one fictional universal campaign.
  • The 108% increase is ESET's comparison of detections between H2 2025 and H1 2026, not a universal prevalence or risk measurement.
  • Report-scoped indicators do not imply current maliciousness, actor-wide ownership, or appearance in every ClickFix event.
  • SOC//LIFE's Case, Detection, and Hunt are defensive portfolio artifacts, not evidence that these campaigns were observed in a customer environment.

How the 2026 examples differed

Huntress's May report followed a compromised website into pcalua.exe, mshta.exe, a remote HTA, curl, a silent MSI, Potemkin and RMMProject, then EtherRAT and hands-on-keyboard activity across 11 hosts.

Its February report followed ClickFix into Matanbuchus 3.0 and AstarionRAT. The operator returned about 17 hours later, then reached a Windows Server and two domain controllers through RDP, PsExec, a rogue administrator account, and Defender exclusions in about 40 minutes.

Microsoft's CrashFix report described a malicious advertisement, a harmful Chrome extension, delayed browser disruption, a fake repair prompt, finger.exe abuse, and a PowerShell and Python RAT chain.

Microsoft's ACR Stealer report described two different post-execution paths: one used WebDAV, rundll32, PowerShell, Python, and blockchain-backed C2; the other used MSHTA, PowerShell, steganography, and in-memory execution.

Defensive lesson

The durable signal is the user-driven execution chokepoint and what happens immediately afterwards. Treat each source's infrastructure as report-scoped context, then correlate arrival, Run activity, native-tool execution, persistence, credential access, and remote-control behavior.

  1. Potemkin Loader & RMMProject: The Anatomy of a ClickFix Attack

    Huntress

  2. A New RAT and a Hands-on-Keyboard Intrusion

    Huntress

  3. New Clickfix variant ‘CrashFix’ deploying Python Remote Access Trojan

    Microsoft Security

  4. ACR Stealer: Two observed intrusion chains amid increased threat activity

    Microsoft Security

  5. ESET Threat Report H1 2026

    ESET

  6. User Execution: Malicious Copy and Paste

    MITRE ATT&CK

  7. Think before you Click(Fix): Analyzing the ClickFix social engineering technique

    Microsoft Security

Supporting context

ATT&CK mappings

Behavior comes first. These mappings do not imply attribution or complete coverage.