ClickFix Tactic

State-Sponsored Hackers Exploit ClickFix Tactic in Sophisticated Malware Campaigns

State-Sponsored Hackers Exploit ClickFix Tactic in Sophisticated Malware Campaigns

Introduction

Multiple state-sponsored hacking groups from Iran, North Korea, and Russia have been found leveraging the increasingly popular ClickFix social engineering tactic to deploy malware over three months from late 2024 through the beginning of 2025. GetMyIndia.com

The phishing campaigns adopting the strategy have been attributed to clusters tracked as TA427 (aka Kimsuky), TA450 (aka Muddy Water), UNK Remote Rogue, and TA422 (aka APT28). ClickFix has been an initial access technique primarily affiliated with cybercrime groups, although the effectiveness of the approach has led to it also being adopted by nation-state groups

About ClickFix Tactic

The incorporation of ClickFix is