Tag: ClickFix Tactic

State-Sponsored Hackers Weaponize ClickFix Tactic in Targeted Malware Campaigns
News

State-Sponsored Hackers Weaponize ClickFix Tactic in Targeted Malware Campaigns

Over the course of three months, from late 2024 to early 2025, several state-sponsored cyber groups from Russia, North Korea, and Iran have been discovered using the increasingly common ClickFix social engineering technique to spread malware. Clusters identified as TA427 (also known as Kimsuky), TA450 (also known as MuddyWater, UNK_RemoteRogue), and TA422 (also known as APT28) have been linked to the phishing attacks that have adopted the tactic. ClickFix is an initial access method that has been mainly associated with cybercrime organizations, although nation-state organizations have also adopted it due to its efficacy. According to business security firm Proofpoint, ClickFix is replacing the installation and execution phases of current infection chains rather than completely ch...