01A lure reaches the user
Public reporting describes phishing, malicious advertising, compromised websites, and harmful browser extensions as different arrival paths.
Useful logs: Network, Dns, Endpoint
Threat report
2026 reporting shows ClickFix evolving across fake fixes, RAT delivery, credential theft, and hands-on-keyboard intrusion activity.
Reported facts and defensive takeaways are labeled separately.
Public reporting
ClickFix remained a fast-moving social-engineering technique in 2026 because attackers could change the lure, payload, and infrastructure while preserving the same core action: convince the user to execute attacker-supplied code. Public reporting documented distinct RAT, stealer, browser-disruption, and hands-on-keyboard outcomes rather than one universal chain.
The user can become the execution mechanism, native tools can blend with legitimate administration, and one foothold can progress into credential theft, remote access, or lateral movement. ESET reported a 108% increase in ClickFix detections between H2 2025 and H1 2026, reinforcing the need to correlate arrival, endpoint, and network behavior.
Public reporting
01Public reporting describes phishing, malicious advertising, compromised websites, and harmful browser extensions as different arrival paths.
Useful logs: Network, Dns, Endpoint
02The lure asks the user to perform a verification or repair action. CrashFix added deliberate browser disruption before presenting the fake warning.
Useful logs: Endpoint, Network
03The core ClickFix action moves execution through Windows Run, a shell, a terminal, or another user-driven path.
Useful logs: Registry, Process
04Reported chains use different combinations of pcalua, MSHTA, msiexec, finger, rundll32, PowerShell, Python, WebDAV, curl, and in-memory execution.
Useful logs: Process, Network, File
05Huntress documented Potemkin, RMMProject, EtherRAT, Matanbuchus, and AstarionRAT outcomes; Microsoft documented a Python RAT and separate ACR Stealer chains.
Useful logs: Process, Network, File, Endpoint
06Reported examples include Run keys, scheduled tasks, and other chain-specific persistence; these mechanisms are not asserted for every ClickFix event.
Useful logs: Registry, Process, File
07Huntress and Microsoft reporting includes browser credential, cookie, token, and document theft in specific chains.
Useful logs: Endpoint, File, Authentication
08Huntress documented later operator activity using RDP, PsExec, WMIExec, SMBExec, tunneling, rogue accounts, and Defender changes. These actions belong to the cited intrusions, not every ClickFix chain.
Useful logs: Process, Network, Registry, Authentication, Endpoint
Defensive takeaways
RunMRU can preserve the user-driven execution chokepoint even when the lure, payload, and infrastructure rotate.
Useful logs: Registry
Arrival context followed by user execution is more discriminating than either event alone.
Useful logs: Network, Endpoint, Process
The individual tools are legitimate, but their parentage, command line, user context, and immediate follow-on behavior can reveal the delivery path.
Useful logs: Process, Registry
This sequence connects user execution to delivery of the next stage.
Useful logs: Process, Network, File
Close-in-time startup changes can show that a one-time prompt produced a durable foothold.
Useful logs: Registry, Process
Credential-access behavior raises the response priority beyond initial execution and can create cloud or browser session exposure.
Useful logs: Endpoint, File, Authentication
These behaviors can mark progression from initial access into interactive control and wider compromise.
Useful logs: Process, Registry, Network, Endpoint
RunMRU and startup locations connect the user-driven command with later persistence.
Process parentage and command lines show how a browser or user action became native-tool retrieval and execution.
Web, proxy, DNS, and endpoint connections preserve arrival context, remote retrieval, C2, and wider exposure.
File names, paths, hashes, and initiating processes connect retrieval with loader, stealer, or RAT execution.
Endpoint context brings together browser access, credential activity, security-control state, tunnels, remote execution, and persistence.
Defensive takeaways
Correlate a suspicious RunMRU command with same-device native-tool execution that retrieves remote content or silently launches a package inside a short window.
Add weight when the same device creates startup persistence, contacts new infrastructure, accesses browser data, impairs security controls, creates a tunnel, or begins remote execution.
Defensive takeaways
Derive the Run time from endpoint telemetry, recover the preceding URL or referrer where retained, and search it across users and devices before expanding through source-scoped infrastructure.
Search RunMRU, native-tool execution, silent packages, Run keys, credential access, Defender changes, tunnels, and remote execution so infrastructure rotation does not end the hunt.
Public reporting
13 valuescl[.]distritovagas[.]comsonra[.]eutialyson[.]comanus-staylard[.]xyzresumeacceptable[.]com77[.]110[.]122[.]58213[.]165[.]41[.]26RunSearch.exe2abe5dd3a057fdef935722e50e9251c272d29fd26113187b853a1f9a9cb89d9binst24.msi79f7b67ce8b39070f3e1c2b90fce0ce84134782a7dedcccc1edac197ee9e089bavast_update.bin3b7ae925e2d64522b4f69b56285b05aeca8c5aab5ab46a9c02c4fafb69d881ce0xb3f2897f2bc797e5b9033faef8c81e92b01cb8317 valueshttp[:]//binclloudapp[.]com/466943https[:]//marle[.]io/check/updprofile[.]aspxwww[.]ndibstersoft[.]comSystemStatus.dll6ffae128e0dbf14c00e35d9ca17c9d6c81743d1fc5f8dd4272a03c66ecc1ad1fBeacon.exeeecc83add16f3d513a9701e9a646b1885014229ac6f86addd6b10afb64d1d2af10 valuesnexsnield[.]com69[.]67[.]173[.]30144[.]31[.]221[.]197158[.]247[.]252[.]178170[.]168[.]103[.]208c46af9ae6ab0e7567573dbc950a8ffbe30ea848fac90cd15860045fe7640199cct.exebeb0229043741a7c7bfbb4f39d00f583e37ea378d11ed3302d0a2bc30f267006script.ps1c76c0146407069fd4c271d6e1e03448c481f0970ddbe7042b31f552e37b5581716 valueslooksta[.]icucontrite[.]quirksturdy[.]icuux[.]strainedeasily[.]icucpppemwjewjoiwejow[.]salebreaksd[.]wifihot[.]icuwalter[.]filloco[.]icufast[.]raidher[.]icuapigrokcloud[.]icuenhanceblabber[.]ccdeep-harborio[.]comauramatrixa[.]comzealpraxis[.]comprism-vertex[.]comprism-matrixs[.]comproton-network[.]comcreativecommunityinfo[.]artReview record
The approved source set covers Microsoft's January and February CrashFix observations, Huntress intrusions reported in February and May, ACR Stealer activity observed from late April to mid-June, and Microsoft's July publication. It does not claim continuous activity or one shared campaign.
Multiple first-party investigations and vendor reports independently document the stable user-driven execution pattern and materially different 2026 payload chains. Confidence remains bounded to the cited reporting; ClickFix is not attributed to one actor, and no single payload, infrastructure set, or follow-on behavior is universal.
Huntress's May report followed a compromised website into pcalua.exe, mshta.exe, a remote HTA, curl, a silent MSI, Potemkin and RMMProject, then EtherRAT and hands-on-keyboard activity across 11 hosts.
Its February report followed ClickFix into Matanbuchus 3.0 and AstarionRAT. The operator returned about 17 hours later, then reached a Windows Server and two domain controllers through RDP, PsExec, a rogue administrator account, and Defender exclusions in about 40 minutes.
Microsoft's CrashFix report described a malicious advertisement, a harmful Chrome extension, delayed browser disruption, a fake repair prompt, finger.exe abuse, and a PowerShell and Python RAT chain.
Microsoft's ACR Stealer report described two different post-execution paths: one used WebDAV, rundll32, PowerShell, Python, and blockchain-backed C2; the other used MSHTA, PowerShell, steganography, and in-memory execution.
The durable signal is the user-driven execution chokepoint and what happens immediately afterwards. Treat each source's infrastructure as report-scoped context, then correlate arrival, Run activity, native-tool execution, persistence, credential access, and remote-control behavior.
Huntress
Huntress
Microsoft Security
Microsoft Security
ESET
MITRE ATT&CK
Microsoft Security
Supporting context
T1204.004 · Malicious Copy and PasteThe stable ClickFix behavior convinces a user to copy and execute attacker-supplied code.
T1218.005 · MshtaPublic 2026 reporting includes MSHTA delivery and execution chains.
T1218.007 · MsiexecHuntress reporting includes silent MSI delivery after ClickFix execution.
T1059.001 · PowerShellMicrosoft reporting includes PowerShell in CrashFix and ACR Stealer delivery chains.
T1105 · Ingress Tool TransferThe documented chains retrieve loaders, scripts, packages, or other remote content.
T1547.001 · Registry Run Keys / Startup FolderHuntress reported Run-key persistence after the initial foothold.
T1555.003 · Credentials from Web BrowsersReported outcomes include browser credential, cookie, and token theft.
T1685 · Disable or Modify ToolsHuntress reported Defender exclusions and service changes as Disable or Modify Tools behavior.
T1047 · Windows Management InstrumentationThe May Huntress intrusion included WMIExec behavior during lateral movement.
T1021.002 · SMB/Windows Admin SharesThe May Huntress intrusion included SMBExec behavior and administrative-share use.