🛠️ ClickFix Techniques

These are examples of different social engineering techniques utilized by attackers to trick users into running malicious commands. Use this information for educational and defensive purposes.

Platform
Windows
Mac
Linux
Interface
GUI
CLI
Capabilities
UAC
MOTW
File Explorer
conhost.exe
windows cli UAC
2 lures
Steganography ClickFix (Stego Loader)
windows browser Cache Smuggling Fileless Execution Local Execution Memory-only Malware PowerShell Service Worker Abuse Steganography
2 lures
osascript
mac cli CLI Credential Theft Data Exfiltration
1 lure
explorer shell URIs
windows gui File Explorer GUI
2 lures
search-ms protocol
windows gui File Explorer GUI
1 lure
Office URI schemes (ms-word/ms-excel)
windows gui File Explorer GUI
1 lure
regasm.exe
windows cli MOTW UAC
2 lures
FileFix (Explorer address bar)
windows gui CLI File Explorer GUI
3 lures
finger.exe
windows cli CLI
1 lure
forfiles.exe
windows cli CLI File Explorer
4 lures
ftp.exe
windows cli UAC
2 lures
net use (WebDAV)
windows cli CLI
1 lure
CrashFix
windows browser CLI GUI
1 lure
ClickOnce launcher (dfshim)
windows gui GUI
1 lure
certutil.exe
windows cli MOTW UAC
2 lures
credwiz.exe
windows gui File Explorer MOTW UAC
2 lures
wextract.exe
windows gui CLI File Explorer GUI
2 lures
certreq.exe
windows cli File Explorer MOTW UAC
2 lures
perfmon.exe
windows gui File Explorer GUI
1 lure
control.exe
windows gui File Explorer GUI MOTW UAC
3 lures
CompMgmtLauncher.exe
windows gui File Explorer GUI
4 lures
ssh.exe
windows cli CLI UAC
1 lure
ConsentFix
windows browser GUI
1 lure
fsquirt.exe
windows gui File Explorer GUI
1 lure
taskmgr.exe
windows gui File Explorer GUI
1 lure
wt.exe
windows cli CLI
1 lure
Terminal
mac cli CLI Credential Theft Data Exfiltration Persistence
2 lures
eventvwr.exe
windows gui File Explorer GUI
2 lures
mshta.exe
windows cli MOTW UAC
2 lures
MRT.exe
windows gui File Explorer MOTW UAC
2 lures
powershell.exe
windows cli MOTW UAC
2 lures
cmd.exe
windows cli UAC
2 lures
iexpress.exe
windows gui File Explorer GUI
1 lure
DxDiag.exe
windows gui File Explorer MOTW
1 lure
FileHistory.exe
windows gui File Explorer MOTW UAC
2 lures
msbuild.exe
windows cli MOTW UAC
2 lures
wusa.exe
windows cli CLI
1 lure
msiexec.exe
windows cli CLI
1 lure
dcomcnfg.exe
windows gui File Explorer GUI
1 lure
DriveSurge / zTDS ClickFix
cross-platform browser CLI GUI
2 lures
Fake Google Meet ClickFix
windows browser Clipboard Hijack PowerShell Social Engineering Video Tutorial
3 lures
rundll32.exe
windows cli MOTW UAC
2 lures
nslookup.exe
windows cli CLI
1 lure
wscript.exe
windows cli MOTW UAC
2 lures
colorcpl.exe
windows gui File Explorer MOTW
2 lures
msra.exe
windows gui File Explorer MOTW
1 lure