typeentityconfidencemediumcreated2026-08-16updated2026-08-16malware-familyloaderbrowser-extensiondefense-evasionsocial-engineeringinfostealer

ClickFix

Social-engineering campaign delivering a fake CAPTCHA / "I'm not a robot" prompt on compromised websites. Victims are instructed to copy a PowerShell command and paste it into the Win+R run dialog, which downloads and executes a stage-2 payload. Also tracked as ClearFake in public reporting.

Distribution

  • Stage 1: Compromised or malicious websites display a fake CAPTCHA overlay. Clicking "Verify" copies a PowerShell one-liner to the clipboard with instructions to press Win+R, Ctrl+V, Enter.
  • Stage 2: The PowerShell downloads a PE payload (often PyInstaller-packed) that unpacks a browser-extension sideload package and/or a secondary infostealer binary.

Observed Tooling

  • PyInstaller one-file mode with Python 3.x embedded runtime.
  • PyArmor or PyArmor-like runtime obfuscation for the Python payload.
  • Browser-extension sideload via data_p002\*.js + *.xml + pack.js + uusd.exe pattern.

Capabilities

  • social-engineering-fake-captcha
  • clipboard-powershell-paste
  • pyinstaller-packed-dropper
  • pyarmor-obfuscated-payload
  • browser-extension-sideload-crx3
  • browser-credential-harvesting
  • registry-extension-policy-persistence
  • secondary-binary-drop-uusd

ATT&CK Mapping

  • T1566.002 — Spearphishing Link (compromised websites)
  • T1059.001 — PowerShell (stage-1 clipboard payload)
  • T1555.003 — Credentials from Web Browsers (extension-based harvesting)
  • T1176 — Browser Extensions (sideload for persistence and access)
  • T1112 — Modify Registry (ExtensionInstallForcelist policy)

Cross-References

Siblings

  • d8f02277 — PyInstaller 6.x + Python 3.13 + PyArmor + data_p002 extension package. Static-only. ^[/intel/analyses/d8f0227793cbb22d7d2ed3522ab006b9959c348db25878325dc82b7cfecdbfb1.html]

Confidence

Medium. OpenCTI labels clickfix and efimer anchor the campaign attribution, but payload content was not extracted for behavioral confirmation. The data_p002 extension filenames are strongly indicative but remain unverified.