Meet IClickFix: a widespread framework using the ClickFix tactic
IClickFix is a malicious framework that compromises WordPress sites to distribute malware using the ClickFix social engineering tactic. Active since December 2024, it has infected over 3,800 WordPress sites globally. The framework injects malicious JavaScript into compromised sites, leading users through a fake CAPTCHA challenge that tricks them into executing malicious code. This ultimately installs NetSupport RAT, granting attackers full control of infected systems. The campaign has evolved over time, adding traffic distribution systems and refining its lures. While initially distributing Emmenhtal Loader and XFiles Stealer, it now primarily delivers NetSupport RAT. The widespread nature of the attacks suggests opportunistic exploitation rather than targeted campaigns.
Pulse ID: 697c69b9af67a1f288275176
Pulse Link: https://otx.alienvault.com/pulse/697c69b9af67a1f288275176
Pulse Author: AlienVault
Created: 2026-01-30 08:20:09
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CAPTCHA #CyberSecurity #InfoSec #Java #JavaScript #Malware #NetSupport #NetSupportRAT #OTX #OpenThreatExchange #RAT #RDP #SocialEngineering #Word #Wordpress #bot #AlienVault