Clickfix: Copy, Paste, Compromise

ClickFix is an evolving social engineering technique that tricks users with fake CAPTCHAs or software updates into manually executing malicious scripts via Windows Run or the macOS Terminal. This approach often bypasses antivirus (AV) and endpoint detection and response (EDR) systems by using trusted system tools (LOLBins) and in-memory execution, thereby mimicking expected user behaviour. This presentation explores the malware-as-a-service (MaaS) ecosystem underpinning these toolkits, which contain payloads like Lumma and DarkGate. It concludes with an analysis of a real-world attack on a Croatian student association website in April 2026, providing actionable indicators of compromise (IOCs), custom YARA rules and behavioural hardening strategies for defenders.

    Speaker

    FURTHER SESSIONS

  • 1979 called. They already figured it out.

  • A Few Dollars to Disappear: Breaking C2 Beaconing Detection

  • Ants, Bricks and Spiders: Threat Emulation on the VMware Stack

  • Capture The Flag

  • Join us in Amsterdam!

    November 19, 2026

    Hang out, learn something awesome and make new friends.

    Get Tickets