216.73.217.22

PHISH ALERT: From a Simple Phishing Email to a Full Attack Arsenal: The Evolution of "ClickFix"

· Published 23/06/2026 14:11

Export JSON

Essential information

Published
23/06/2026 14:11
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
clickfix credential harvesting dns txt staging phishing campaign powershell rmm tools social engineering spyware
Related entities
6 indicators, 3 observables, 20 techniques (mitre)

Description

A sophisticated leverages evolved techniques to bypass modern endpoint security through victim-assisted execution. Targets receive emails with urgent OneDrive document lures containing malicious ZIP attachments. The attack uses LNK shortcuts that redirect victims to landing pages, silently injecting commands into their clipboard. Through , victims are tricked into manually executing commands via Win+R, circumventing traditional security filters. The campaign employs DNS TXT records for payload staging, avoiding HTTP detection. The threat infrastructure hosts multiple malicious components including obfuscated scripts, fake MSI installers masquerading as legitimate software like ConnectWise, and ISO images with for persistent access. This represents a shift toward long-game tactics focused on establishing full post-compromise environmental control.

External references