s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.iclickfix

📛 Threat Title

Malware family: IClickFix

Category: IClickFix First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.iclickfix`. Printable name: IClickFix.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.iclickfix VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.iclickfix

IOC database

Type
domain
Value
js.iclickfix
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.iclickfix

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.iclickfix

References (1)

Remediations (10)

  • web:blog.sekoia.io

    Uncover IClickFix : a malicious framework exploiting the ClickFix tactic in widespread malware campaigns to deliver NetSupport RAT.

  • web:community.gurucul.com

    This article provides hunting tips and mitigation strategies for ClickFix campaigns, along with insights into major 2025 incidents. Notable cases include NetSupport RAT with a new loader, Latrodectus malware using ClickFix lures, and widespread Lumma Stealer activity.

  • web:malpedia.caad.fkie.fraunhofer.de

    IClickFix is a malicious JavaScript framework deployed on compromised WordPress sites to deliver further malware using the ClickFix social engineering tactic and fake Cloudflare Turnstile CAPTCHA challenge.

  • web:protectyourwp.com

    The IClickFix framework serves as a widespread and persistent initial access vector, leveraging the ClickFix social engineering tactic for malware distribution.

  • web:socprime.com

    The report profiles IClickFix , a malicious JavaScript framework that compromises WordPress sites and presents a spoofed Cloudflare Turnstile-style CAPTCHA. The lure coerces visitors into executing a PowerShell command that downloads and installs NetSupport RAT.

  • web:undercodetesting.com

    The IClickFix campaign demonstrates that simple, creative modifications to existing attack chains can defeat many security products that only look for known malware signatures. By abusing SSH - a protocol often allowed outbound for legitimate administration - attackers gain a stealthy command channel.

  • web:unit42.paloaltonetworks.com

    Executive Summary In this article, we share hunting tips and mitigation strategies for ClickFix campaigns and provide an inside view of some of the most prominent ClickFix campaigns we have seen so far in 2025: Attackers distributing NetSupport remote access Trojan (RAT) are ramping up activities with a new loader Attackers distributing Latrodectus malware are luring victims with a new ...

  • web:windowsforum.com

    The "Windows Update" screen you trust has been weaponized: attackers are using a high-fidelity fake update pop-up to trick Windows users into pasting and executing a malicious command that boots a fileless, in‑memory infostealer — a fresh and dangerous iteration of the ClickFix social‑engineering family . Background / Overview ClickFix is not a single piece of malware but a social ...

  • web:www.eset.com

    "The list of threats that ClickFix attacks lead to is growing by the day, including infostealers, ransomware, remote access trojans, cryptominers, post-exploitation tools, and even custom malware from nation-state-aligned threat actors," says Jiří Kropáč, Director of Threat Prevention Labs at ESET.

  • web:www.microsoft.com

    The ClickFix social engineering technique has been growing in popularity, with campaigns targeting thousands of enterprise and end-user devices daily. This technique exploits users' tendency to resolve technical issues by tricking them into running malicious commands. These commands, in turn, deliver payloads that ultimately lead to information theft and exfiltration.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.