• News/
  • https://www.bleepingcomputer.com/news/security/state-sponsored-hackers-embrace-clickfix-social-engineering-tactic/

State-sponsored hackers embrace ClickFix social engineering tactic

BleepingComputer
·
Bill Toulas
·
Published Apr 20, 2025
·
Updated

ClickFix attacks are gaining traction among threat actors, with multiple advanced persistent threat (APT) groups from North Korea, Iran, and Russia adopting the technique in recent espionage campaigns. ClickFix is a social engineering tactic where malicious websites impersonate legitimate software or document-sharing platforms. Targets are lured via phishing or malvertising and shown fake error messages that claim a document or download failed. Victims are then prompted to click a "Fix" button, which instructs them to run a PowerShell or command-line script, leading to the execution of malware on their devices. Microsoft's Threat Intelligence team reported last February that the North Korean state actor 'Kimsuky' was also using it as part of a fake "device registration" web page. A new report from Proofpoint reveals that, between late 2024 and early 2025, Kimsuky (North Korea), MuddyWater (Iran), and also APT28 and UNK_RemoteRogue (Russia) have all used ClickFix in their targeted espionage operations. Starting with Kimsuky, the attacks were observed between January and February 2025, targeting think tanks focused on North Korea-related policy. The DPRK hackers used spoofed Korean, Japanese, or English emails to appear as if the sender was a Japanese diplomat to initiate contact with the target. After establishing trust, the attackers sent a malicious PDF file linking to a fake secure drive that prompted the target to "register" by manually copying a PowerShell command into t...

Read full article

Affected Software

4 affected components
Microsoft PowerShell
Microsoft Office
Zimbra Zimbra
Google Spreadsheet

Frequently Asked Questions

1

What is the ClickFix social engineering tactic?

ClickFix is a social engineering technique utilized by hackers to manipulate users into clicking on malicious links or attachments.

2

Which countries are associated with the use of ClickFix in hacking campaigns?

The ClickFix tactic has been adopted by advanced persistent threat (APT) groups from North Korea, Iran, and Russia.

3

What are the recent targets of the ClickFix attacks?

Recent ClickFix attacks have primarily targeted organizations in espionage-related campaigns.

4

What software products are mentioned as affected by the ClickFix tactic?

The ClickFix tactic has implications for Microsoft PowerShell, Microsoft Office, Zimbra, and Google Spreadsheet.

5

How are ClickFix attacks carried out?

ClickFix attacks leverage social engineering to trick users into opening malicious files or links, leading to potential security breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203