Clickfix: Copy, Paste, Compromise
ClickFix is an evolving social engineering technique that tricks users with fake CAPTCHAs or software updates into manually executing malicious scripts via Windows Run or the macOS Terminal. This approach often bypasses antivirus (AV) and endpoint detection and response (EDR) systems by using trusted system tools (LOLBins) and in-memory execution, thereby mimicking expected user behaviour. This presentation explores the malware-as-a-service (MaaS) ecosystem underpinning these toolkits, which contain payloads like Lumma and DarkGate. It concludes with an analysis of a real-world attack on a Croatian student association website in April 2026, providing actionable indicators of compromise (IOCs), custom YARA rules and behavioural hardening strategies for defenders.
Speaker

Toni Dujmović
Threat Analyst at ReversingLabs
Toni Dujmović is a Threat Analyst dedicated to turning cutting-edge threat research into precise security solutions. By bridging the gap between researchers and developers, he helps build tools that accurately identify real threats and ruthlessly eliminate false positives.... read more