🛠️ ClickFix Techniques

These are examples of different social engineering techniques utilized by attackers to trick users into running malicious commands. Use this information for educational and defensive purposes.

Platform
Windows
Mac
Linux
Interface
GUI
CLI
Capabilities
UAC
MOTW
File Explorer
fsquirt.exe
windows gui File Explorer GUI
1 lure
msbuild.exe
windows cli MOTW UAC
2 lures
Fake Google Meet ClickFix
windows browser Clipboard Hijack PowerShell Social Engineering Video Tutorial
3 lures
CompMgmtLauncher.exe
windows gui File Explorer GUI
4 lures
wextract.exe
windows gui CLI File Explorer GUI
2 lures
mshta.exe
windows cli MOTW UAC
2 lures
control.exe
windows gui File Explorer GUI MOTW UAC
3 lures
ClickOnce launcher (dfshim)
windows gui GUI
1 lure
ftp.exe
windows cli UAC
2 lures
FileFix (Explorer address bar)
windows gui CLI File Explorer GUI
3 lures
wt.exe
windows cli CLI
1 lure
regasm.exe
windows cli MOTW UAC
2 lures
taskmgr.exe
windows gui File Explorer GUI
1 lure
rundll32.exe
windows cli MOTW UAC
2 lures
msra.exe
windows gui File Explorer MOTW
1 lure
search-ms protocol
windows gui File Explorer GUI
1 lure
explorer shell URIs
windows gui File Explorer GUI
2 lures
cmd.exe
windows cli UAC
2 lures
wscript.exe
windows cli MOTW UAC
2 lures
forfiles.exe
windows cli CLI File Explorer
4 lures
net use (WebDAV)
windows cli CLI
1 lure
CrashFix
windows browser CLI GUI
1 lure
Steganography ClickFix (Stego Loader)
windows browser Cache Smuggling Fileless Execution Local Execution Memory-only Malware PowerShell Service Worker Abuse Steganography
2 lures
Office URI schemes (ms-word/ms-excel)
windows gui File Explorer GUI
1 lure
colorcpl.exe
windows gui File Explorer MOTW
2 lures
DxDiag.exe
windows gui File Explorer MOTW
1 lure
dcomcnfg.exe
windows gui File Explorer GUI
1 lure
MRT.exe
windows gui File Explorer MOTW UAC
2 lures
conhost.exe
windows cli UAC
2 lures
powershell.exe
windows cli MOTW UAC
2 lures
ConsentFix
windows browser GUI
1 lure
osascript
mac cli CLI Credential Theft Data Exfiltration
1 lure
certreq.exe
windows cli File Explorer MOTW UAC
2 lures
perfmon.exe
windows gui File Explorer GUI
1 lure
wusa.exe
windows cli CLI
1 lure
FileHistory.exe
windows gui File Explorer MOTW UAC
2 lures
finger.exe
windows cli CLI
1 lure
certutil.exe
windows cli MOTW UAC
2 lures
credwiz.exe
windows gui File Explorer MOTW UAC
2 lures
msiexec.exe
windows cli CLI
1 lure
nslookup.exe
windows cli CLI
1 lure
Terminal
mac cli CLI Credential Theft Data Exfiltration Persistence
2 lures
eventvwr.exe
windows gui File Explorer GUI
2 lures
ssh.exe
windows cli CLI UAC
1 lure
iexpress.exe
windows gui File Explorer GUI
1 lure