A new wave of sophisticated cyberattacks is emerging, as threat actors refine their tactics to evade detection and gain a foothold in unsuspecting networks. The ClickFix technique, which exploits human problem-solving tendencies and trust in software, has become increasingly prevalent in recent years. Now, attackers are taking it to the next level by hiding malicious payloads until after the victim has taken the initial trusted action.
The technique typically involves presenting victims with a fake technical problem or verification prompt, instructing them to paste and execute a command that often already resides on their clipboard. This can be masked as a legitimate issue, such as a required Zoom update or a CAPTCHA puzzle. Once the command is executed, the malicious payload is delivered, giving attackers access to the victim’s system.
However, researchers from Flare and Microsoft Threat Intelligence have uncovered two recent examples of how ClickFix attacks are evolving to evade detection measures. In one campaign, victims were directed to a website displaying a blurred house-wiring diagram with a deliberately misspelled domain name. Upon visiting this page, users were prompted with a fake reCAPTCHA checkbox next to a spoofed Cloudflare logo and classic “Open PowerShell and paste the text” instructions.
But instead of directly retrieving the next-stage payload, the pasted PowerShell command queries a DNS TXT record through an attacker-controlled DNS server. The record returned by that server contains the next PowerShell instruction, effectively telling the system where to go next. This additional step allows the infection chain to progress further before some defenses have enough context to recognize what’s happening.
This tactic is particularly insidious because it keeps the next-stage instruction out of the command directly copied to the victim’s clipboard. As a result, forensic analysis may be more difficult, as there are fewer clues to work with. Furthermore, Flare researchers discovered an unexecuted Python launcher in the malware package that suggests the developers were experimenting with different payload strategies depending on the victim environment.
In another example, Microsoft Threat Intelligence uncovered a ClickFix campaign involving a “cluster” of compromised websites. In this case, the user visits a website, and that website pre-fetches a script payload into the browser cache disguised as a PNG file. This happens before the user is instructed to paste malicious code copied to the clipboard.
When the victim executes the malicious command, the cached website content is already on the device, loaded, and ready to be executed. This helps hide the payload script and bypasses the character limit of the Run dialog. The cached payload then reaches back out for additional PowerShell and later-stage payloads, which Endpoint Detection and Response (EDR) tools can still possibly catch.
These examples demonstrate how threat actors are refining their tactics to evade detection measures and gain a foothold in unsuspecting networks. As attackers continue to evolve, it’s essential that organizations remain vigilant and take proactive steps to mitigate these threats. By being aware of the latest tactics and staying up-to-date with security patches and best practices, businesses can reduce their risk exposure and protect themselves against these sophisticated cyberattacks.
Ultimately, this highlights the importance of user education and awareness in preventing these types of attacks. By being cautious when interacting with suspicious websites or prompts, users can significantly reduce the effectiveness of ClickFix campaigns.
Source: Dark Reading — 2026-10-06