ClickFix Campaigns Abuse Legitimate Services for Persistent Access
C darkreading ·
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
ClickFix campaigns use legitimate system services for persistent attacks and therefore require user awareness rather than pure patch management.
Description
ClickFix is a social engineering technique in which attackers display fake captcha or error messages that trick victims into pasting a malicious command into the Windows Run dialog or PowerShell. The campaign abuses legitimate services and system tools to gain persistent access to compromised systems. Two recent attack waves show that the method is actively being further developed and used by various threat actors. Organizations whose employees use Windows workstations and common browsers or collaboration platforms such as Microsoft Teams are affected. There are no CVE IDs; the attacks are actively circulating.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 0.00
- industry weight
- 1.10
- freshness factor
- 0.70
- exploitability factor
- 1.00
- days old
- 5.00
- vendor mismatch penalty
- 0.00
Path: operational