ClickFix
Social-engineering campaign delivering a fake CAPTCHA / "I'm not a robot" prompt on compromised websites. Victims are instructed to copy a PowerShell command and paste it into the Win+R run dialog, which downloads and executes a stage-2 payload. Also tracked as ClearFake in public reporting.
Distribution
- Stage 1: Compromised or malicious websites display a fake CAPTCHA overlay. Clicking "Verify" copies a PowerShell one-liner to the clipboard with instructions to press Win+R, Ctrl+V, Enter.
- Stage 2: The PowerShell downloads a PE payload (often PyInstaller-packed) that unpacks a browser-extension sideload package and/or a secondary infostealer binary.
Observed Tooling
- PyInstaller one-file mode with Python 3.x embedded runtime.
- PyArmor or PyArmor-like runtime obfuscation for the Python payload.
- Browser-extension sideload via
data_p002\*.js+*.xml+pack.js+uusd.exepattern.
Capabilities
- social-engineering-fake-captcha
- clipboard-powershell-paste
- pyinstaller-packed-dropper
- pyarmor-obfuscated-payload
- browser-extension-sideload-crx3
- browser-credential-harvesting
- registry-extension-policy-persistence
- secondary-binary-drop-uusd
ATT&CK Mapping
- T1566.002 — Spearphishing Link (compromised websites)
- T1059.001 — PowerShell (stage-1 clipboard payload)
- T1555.003 — Credentials from Web Browsers (extension-based harvesting)
- T1176 — Browser Extensions (sideload for persistence and access)
- T1112 — Modify Registry (ExtensionInstallForcelist policy)
Cross-References
- browser-extension-sideload-crx3 — technique for forcing Chrome extension installation
- browser-credential-harvesting — post-installation credential theft
- pyarmor-runtime-obfuscation — payload protection technique
Siblings
d8f02277— PyInstaller 6.x + Python 3.13 + PyArmor +data_p002extension package. Static-only. ^[/intel/analyses/d8f0227793cbb22d7d2ed3522ab006b9959c348db25878325dc82b7cfecdbfb1.html]
Confidence
Medium. OpenCTI labels clickfix and efimer anchor the campaign attribution, but payload content was not extracted for behavioral confirmation. The data_p002 extension filenames are strongly indicative but remain unverified.