🛠️ ClickFix Techniques

These are examples of different social engineering techniques utilized by attackers to trick users into running malicious commands. Use this information for educational and defensive purposes.

Platform
Windows
Mac
Linux
Interface
GUI
CLI
Capabilities
UAC
MOTW
File Explorer
colorcpl.exe
windows gui File Explorer MOTW
2 lures
iexpress.exe
windows gui File Explorer GUI
1 lure
powershell.exe
windows cli MOTW UAC
2 lures
search-ms protocol
windows gui File Explorer GUI
1 lure
regasm.exe
windows cli MOTW UAC
2 lures
ftp.exe
windows cli UAC
2 lures
Steganography ClickFix (Stego Loader)
windows browser Cache Smuggling Fileless Execution Local Execution Memory-only Malware PowerShell Service Worker Abuse Steganography
2 lures
dcomcnfg.exe
windows gui File Explorer GUI
1 lure
rundll32.exe
windows cli MOTW UAC
2 lures
credwiz.exe
windows gui File Explorer MOTW UAC
2 lures
msra.exe
windows gui File Explorer MOTW
1 lure
msbuild.exe
windows cli MOTW UAC
2 lures
fsquirt.exe
windows gui File Explorer GUI
1 lure
eventvwr.exe
windows gui File Explorer GUI
2 lures
certutil.exe
windows cli MOTW UAC
2 lures
wscript.exe
windows cli MOTW UAC
2 lures
explorer shell URIs
windows gui File Explorer GUI
2 lures
Office URI schemes (ms-word/ms-excel)
windows gui File Explorer GUI
1 lure
perfmon.exe
windows gui File Explorer GUI
1 lure
FileFix (Explorer address bar)
windows gui CLI File Explorer GUI
3 lures
forfiles.exe
windows cli CLI File Explorer
4 lures
CompMgmtLauncher.exe
windows gui File Explorer GUI
4 lures
DxDiag.exe
windows gui File Explorer MOTW
1 lure
msiexec.exe
windows cli CLI
1 lure
ClickOnce launcher (dfshim)
windows gui GUI
1 lure
Terminal
mac cli CLI Credential Theft Data Exfiltration Persistence
2 lures
certreq.exe
windows cli File Explorer MOTW UAC
2 lures
taskmgr.exe
windows gui File Explorer GUI
1 lure
Fake Google Meet ClickFix
windows browser Clipboard Hijack PowerShell Social Engineering Video Tutorial
3 lures
osascript
mac cli CLI Credential Theft Data Exfiltration
1 lure
MRT.exe
windows gui File Explorer MOTW UAC
2 lures
wextract.exe
windows gui CLI File Explorer GUI
2 lures
control.exe
windows gui File Explorer GUI MOTW UAC
3 lures
mshta.exe
windows cli MOTW UAC
2 lures
ssh.exe
windows cli CLI UAC
1 lure
conhost.exe
windows cli UAC
2 lures
FileHistory.exe
windows gui File Explorer MOTW UAC
2 lures
wusa.exe
windows cli CLI
1 lure
cmd.exe
windows cli UAC
2 lures