🛠️ ClickFix Techniques

These are examples of different social engineering techniques utilized by attackers to trick users into running malicious commands. Use this information for educational and defensive purposes.

Platform
Windows
Mac
Linux
Interface
GUI
CLI
Capabilities
UAC
MOTW
File Explorer
ssh.exe
windows cli CLI UAC
1 lure
wt.exe
windows cli CLI
1 lure
CompMgmtLauncher.exe
windows gui File Explorer GUI
4 lures
regasm.exe
windows cli MOTW UAC
2 lures
mshta.exe
windows cli MOTW UAC
2 lures
cmd.exe
windows cli UAC
2 lures
Office URI schemes (ms-word/ms-excel)
windows gui File Explorer GUI
1 lure
credwiz.exe
windows gui File Explorer MOTW UAC
2 lures
finger.exe
windows cli CLI
1 lure
taskmgr.exe
windows gui File Explorer GUI
1 lure
msiexec.exe
windows cli CLI
1 lure
Steganography ClickFix (Stego Loader)
windows browser Cache Smuggling Fileless Execution Local Execution Memory-only Malware PowerShell Service Worker Abuse Steganography
2 lures
iexpress.exe
windows gui File Explorer GUI
1 lure
wscript.exe
windows cli MOTW UAC
2 lures
ConsentFix
windows browser GUI
1 lure
ClickOnce launcher (dfshim)
windows gui GUI
1 lure
ftp.exe
windows cli UAC
2 lures
net use (WebDAV)
windows cli CLI
1 lure
wusa.exe
windows cli CLI
1 lure
Terminal
mac cli CLI Credential Theft Data Exfiltration Persistence
2 lures
FileHistory.exe
windows gui File Explorer MOTW UAC
2 lures
msbuild.exe
windows cli MOTW UAC
2 lures
powershell.exe
windows cli MOTW UAC
2 lures
Fake Google Meet ClickFix
windows browser Clipboard Hijack PowerShell Social Engineering Video Tutorial
3 lures
CrashFix
windows browser CLI GUI
1 lure
MRT.exe
windows gui File Explorer MOTW UAC
2 lures
dcomcnfg.exe
windows gui File Explorer GUI
1 lure
rundll32.exe
windows cli MOTW UAC
2 lures
DxDiag.exe
windows gui File Explorer MOTW
1 lure
conhost.exe
windows cli UAC
2 lures
perfmon.exe
windows gui File Explorer GUI
1 lure
fsquirt.exe
windows gui File Explorer GUI
1 lure
control.exe
windows gui File Explorer GUI MOTW UAC
3 lures
forfiles.exe
windows cli CLI File Explorer
4 lures
FileFix (Explorer address bar)
windows gui CLI File Explorer GUI
3 lures
msra.exe
windows gui File Explorer MOTW
1 lure
osascript
mac cli CLI Credential Theft Data Exfiltration
1 lure
explorer shell URIs
windows gui File Explorer GUI
2 lures
colorcpl.exe
windows gui File Explorer MOTW
2 lures
certutil.exe
windows cli MOTW UAC
2 lures
wextract.exe
windows gui CLI File Explorer GUI
2 lures
search-ms protocol
windows gui File Explorer GUI
1 lure
eventvwr.exe
windows gui File Explorer GUI
2 lures
nslookup.exe
windows cli CLI
1 lure
certreq.exe
windows cli File Explorer MOTW UAC
2 lures