🛠️ ClickFix Techniques

These are examples of different social engineering techniques utilized by attackers to trick users into running malicious commands. Use this information for educational and defensive purposes.

Platform
Windows
Mac
Linux
Interface
GUI
CLI
Capabilities
UAC
MOTW
File Explorer
CrashFix
windows browser CLI GUI
1 lure
eventvwr.exe
windows gui File Explorer GUI
2 lures
msbuild.exe
windows cli MOTW UAC
2 lures
finger.exe
windows cli CLI
1 lure
wusa.exe
windows cli CLI
1 lure
taskmgr.exe
windows gui File Explorer GUI
1 lure
ssh.exe
windows cli CLI UAC
1 lure
DxDiag.exe
windows gui File Explorer MOTW
1 lure
ClickOnce launcher (dfshim)
windows gui GUI
1 lure
msiexec.exe
windows cli CLI
1 lure
wextract.exe
windows gui CLI File Explorer GUI
2 lures
rundll32.exe
windows cli MOTW UAC
2 lures
nslookup.exe
windows cli CLI
1 lure
FileFix (Explorer address bar)
windows gui CLI File Explorer GUI
3 lures
wt.exe
windows cli CLI
1 lure
regasm.exe
windows cli MOTW UAC
2 lures
DriveSurge / zTDS ClickFix
cross-platform browser CLI GUI
2 lures
cmd.exe
windows cli UAC
2 lures
explorer shell URIs
windows gui File Explorer GUI
2 lures
forfiles.exe
windows cli CLI File Explorer
4 lures
Terminal
mac cli CLI Credential Theft Data Exfiltration Persistence
2 lures
colorcpl.exe
windows gui File Explorer MOTW
2 lures
ConsentFix
windows browser GUI
1 lure
conhost.exe
windows cli UAC
2 lures
credwiz.exe
windows gui File Explorer MOTW UAC
2 lures
iexpress.exe
windows gui File Explorer GUI
1 lure
search-ms protocol
windows gui File Explorer GUI
1 lure
wscript.exe
windows cli MOTW UAC
2 lures
ftp.exe
windows cli UAC
2 lures
Steganography ClickFix (Stego Loader)
windows browser Cache Smuggling Fileless Execution Local Execution Memory-only Malware PowerShell Service Worker Abuse Steganography
2 lures
CompMgmtLauncher.exe
windows gui File Explorer GUI
4 lures
Office URI schemes (ms-word/ms-excel)
windows gui File Explorer GUI
1 lure
mshta.exe
windows cli MOTW UAC
2 lures
MRT.exe
windows gui File Explorer MOTW UAC
2 lures
msra.exe
windows gui File Explorer MOTW
1 lure
dcomcnfg.exe
windows gui File Explorer GUI
1 lure
Fake Google Meet ClickFix
windows browser Clipboard Hijack PowerShell Social Engineering Video Tutorial
3 lures
osascript
mac cli CLI Credential Theft Data Exfiltration
1 lure
certreq.exe
windows cli File Explorer MOTW UAC
2 lures
certutil.exe
windows cli MOTW UAC
2 lures
fsquirt.exe
windows gui File Explorer GUI
1 lure
control.exe
windows gui File Explorer GUI MOTW UAC
3 lures
FileHistory.exe
windows gui File Explorer MOTW UAC
2 lures
perfmon.exe
windows gui File Explorer GUI
1 lure
net use (WebDAV)
windows cli CLI
1 lure
powershell.exe
windows cli MOTW UAC
2 lures