# ClickFix Malware Goes Industrial: Researcher Exposes Massive API-Driven Delivery Infrastructure
New research into the ClickFix social engineering technique has revealed an alarming infrastructure shift: the malware delivery method has evolved from a crude trick into a sophisticated, commercialized platform that generates customized payloads on demand while actively evading Windows security controls. Researcher Bert-Jan Pals analyzed approximately 3,000 live ClickFix payloads and presented his findings at OrangeCon in early June, exposing how criminal operators have built an "as-a-service" ecosystem that serves malware in 25 languages, automatically targets specific operating systems, and now employs techniques specifically designed to bypass AMSI (Antimalware Scan Interface) detection.
## What Is ClickFix?
ClickFix is a deceptively simple social engineering attack that exploits user trust and procedural muscle memory. The technique operates in three stages:
1. Deceptive presentation: A victim visits a compromised or attacker-controlled page that displays a fake CAPTCHA verification, Windows security alert, or system error message.
2. Hidden payload injection: JavaScript running on the page silently deposits a malicious command into the victim's clipboard.
3. User-executed malware: The page instructs the victim to perform familiar keyboard actions—typically pressing Windows+R and then Ctrl+V to paste and execute—tricking them into running the malware themselves.
The elegance of ClickFix lies in its bypass of traditional defenses. Because the attack relies on user action rather than a zero-day exploit, conventional email filters and endpoint protection systems struggle to detect it. There is often no file to quarantine, no suspicious network connection at the entry point, and no code execution that antivirus software can intercept before the user chooses to paste.
## The Scale of the Threat
The effectiveness of ClickFix has been validated by security telemetry. According to ESET's research, campaigns using the technique surged 517% between late 2024 and the first half of 2025. Microsoft's 2025 Digital Defense Report painted an even starker picture: Defender Experts attributed 47% of initial-access intrusions to ClickFix-style attacks—making it one of the most successful malware delivery vectors tracked by the company.
The success has been formally recognized by the security community. ClickFix now has its own entry in the MITRE ATT&CK framework, cataloged as T1204.004 (User Execution: Malicious Link), cementing its status as a distinct and persistent threat.
## The Industrialization: API-Driven Payload Generation
Pals' analysis revealed the most significant evolution: ClickFix campaigns are no longer run by isolated attackers using static malware samples. Instead, criminal operators have built backend infrastructure that generates unique payloads on demand, similar to how legitimate cloud services handle requests.
### How the Infrastructure Works
When a victim visits a ClickFix page, the JavaScript queries a backend server with an access token. The server logs the request, verifies credentials, and returns a freshly obfuscated malware payload. When Pals requested 100 payloads from the same server, each one was different.
The payloads are wrapped in rotating encryption and encoding schemes:
Once these layers are stripped away, the core payload emerges—typically a PowerShell script designed to execute in memory through a PowerShell runspace, leaving minimal traces on disk.
### Multi-Language, Multi-Platform Service
The platform demonstrates enterprise-grade sophistication in its operations:
This level of operationalization has already attracted secondary markets. ESET has documented criminals selling ready-made ClickFix builders and hosting infrastructure to other attackers, creating a franchise model for malware delivery.
## New Evasion Technique: The Downloads-Folder Method
The second major finding describes how ClickFix operators are evolving to evade AMSI, the Windows Antimalware Scan Interface that allows antivirus software to scan scripts before execution.
### How the AMSI Bypass Works
Rather than copying the entire malware payload to the clipboard, newer ClickFix variants employ a two-stage approach:
1. Silent file download: The malicious webpage quietly downloads a .zip file containing the actual payload to the victim's Downloads folder.
2. Orchestrator command: Only a short, innocuous-looking command is copied to the clipboard—one that moves and extracts the downloaded file, then executes it.
Because AMSI scans clipboard contents before execution, and the clipboard now contains only the orchestrator command (not the payload itself), the malware bypasses antivirus detection. The dangerous code remains hidden in the file sitting in Downloads.
An observed example of the clipboard command reveals the sophistication:
powershell -C "$t=$env:TMP;Move-Item \"$HOME\Downloads\tmp.zip\" \"$t\7947.zip\";tar -xf \"$t\7947.zip\" -C \"$t\";conhost --headless powershell -ExecutionPolicy Bypass -File \"$t\tmp.ps1\" # \"* I am not a robot reCAPTCHA Verification ID:7947 *\""The comment at the end maintains the ruse, appearing to be a verification ID from a fake CAPTCHA.
## Operational Evolution: Leaving Fewer Traces
ClickFix tactics have also evolved to reduce forensic artifacts. The original 2024 campaigns instructed victims to press Windows+R (opening the Run dialog), which leaves behind entries in the system registry's RunMRU key that investigators typically examine.
Newer campaigns, prevalent through 2025 and continuing into 2026, redirect victims to Windows+X and Windows Terminal instead. This shift is tactically significant because:
## State-Sponsored Adoption
ClickFix is no longer exclusively a cybercriminal tool. Proofpoint has attributed ClickFix campaigns to state-backed groups, including:
The adoption by nation-state actors signals that ClickFix has proven effective for initial access operations, which is often the first step in a targeted intrusion leading to data theft, ransomware deployment, or espionage.
---
## HackWire Analysis
What we're seeing here is the maturation of a delivery mechanism from a scrappy proof-of-concept into a professional criminal service. The API-driven infrastructure isn't just an incremental improvement—it's a fundamentally different threat model that defenders must reckon with.
Consider what this means operationally: attackers now have the ability to generate tens of thousands of unique payloads on demand, rotating obfuscation schemes faster than antivirus signatures can be written. Each payload is instrumented and logged, allowing attackers to track which techniques work, which geography has the highest success rate, and which targeting tactics produce the best results. This is industrial-scale malware delivery with real-time telemetry feedback.
The AMSI bypass via Downloads-folder staging is particularly insidious because it exploits a logical separation that Windows itself creates between user downloads and active memory. From the operating system's perspective, a file sitting in Downloads is inert; only when the orchestrator script moves and executes it does the threat materialize. By that point, AMSI has already looked at the clipboard—the wrong stage of the pipeline.
More importantly, this signals that defenders who thought they could detect ClickFix by monitoring for suspicious PowerShell commands in clipboard content are being outmaneuvered. The cat-and-mouse game is shifting. The core payload is now being sealed off from the initial scanning opportunity, forcing defenders to extend detection further downstream—which is harder, slower, and requires more sophisticated monitoring infrastructure.
The shift from RunMRU registry artifacts to Windows Terminal also demonstrates how attackers are learning from forensic post-mortems published in the security community. Every detection guide, every incident report, every DFIR blog post that documents "here's what we found in the registry" becomes a map of what to avoid.
The state-sponsored adoption is the red flag that shouldn't be overlooked. When APT28, MuddyWater, and Kimsuky are all using the same technique, it's not because they suddenly became less sophisticated—it's because they've identified something that works at scale across their target demographics. For a nation-state, reliable initial access is the hardest problem to solve. The fact that they're leveraging ClickFix suggests it solves that problem well enough to make it worth their operational use.
Defenders need to shift from trying to block the payload to blocking the behavioral chain: detecting when files move from Downloads to Temp, detecting when PowerShell conhost runs with headless flags, detecting when Windows Terminal executes base64-encoded scripts, and most importantly, training users to recognize that legitimate system alerts do not require them to paste commands from their clipboard. Until this social engineering vector is addressed at the user education layer, the infrastructure improvements will continue to outpace detection.
— HackWire Editorial
---
## Recommendations for Organizations
Organizations should implement a multi-layered defense strategy:
1. User awareness training: Educate staff that legitimate system alerts will never ask them to copy and paste commands. Legitimate Windows updates and security notifications use GUI dialogs, not clipboard-based instructions.
2. Clipboard monitoring: Deploy endpoint detection and response (EDR) tools that log clipboard operations and flag when commands are pasted directly into PowerShell or command prompts.
3. PowerShell logging: Enable PowerShell Module Logging and Script Block Logging (Windows Event ID 4104) to capture script execution in memory, which can detect even obfuscated payloads.
4. Downloads folder monitoring: Alert on files that are moved from the Downloads folder to temporary directories and then executed.
5. Windows Defender exclusion audit: Ensure that legitimate system exclusions aren't being abused for bypassing AMSI scanning.
6. Browser security: Block JavaScript from accessing clipboard data where organizational policy permits, or enforce tighter controls on clipboard access through browser policies.
---
## Related Coverage