Bluesky · Hashtag

#ClickFix

92
posts · 30d
31
users
3
posts / day
3.0
posts / user
+ 37% vs last week

#ClickFix is an active hashtag on Bluesky. In the last 30 days, 31 people shared 92 posts with it — around 3 a day. Activity is up 37% versus the previous week, peaking on Sep 21 with 10 posts.

#ClickFix posts per day (last 30 days)

Posts with #ClickFix

Brad
@malware-traffic-analysis.net
over 1 year ago
2025-06-18 (Wed): #SmartApeSG --> #ClickFix lure --> #NetSupportRAT --> #StealCv2 A #pcap of the traffic, the malware/artifacts, and some IOCs are available at www.malware-traffic-analysis.net/2025/06/18/i.... Today's the 12th anniversary of my blog, so I made this post a bit more old school.
HTML source of page from legitimate but compromised site showing SmartApeSG injected script.
Example of a ClickFix-style page caused by the injected SmartApeSG script.  A victim must click to get the popup and follow the instructions to paste and run the malicious script.
Traffic from an infection filtered in Wireshark.  This shows the NetSupport RAT C2 traffic and StealC v2 traffic.
1 5 11
Brad
@malware-traffic-analysis.net
almost 2 years ago
2024-12-18 (Wed): #ClickFix style infection chains are still happening, but this method has changed tactics a bit since I last looked into it. Compromised websites are easy to find: urlscan.io/search/#bsc-... Not sure what today's final EXE #infostealer is at polovoiinspektor[.]shop/RalphCvs.exe
2 4 9
Brad
@malware-traffic-analysis.net
9 months ago
2026-01-05 (Monday): #KongTuke domain scrroeder[.]com generated #ClickFix script for 144.31.221[.]71, but I didn't get a malware infection when I tried it today.
Injected KongTuke script in page from compromised website.
Fake CAPTCHA page from KongTuke domain, scrroeder[.]com.
KongTuke's "ClickFix" command injected into the viewer's clipboard.
Traffic from the activity filtered in Wireshark. I did not get the malware from this.
0 1 7
ESET Research
@esetresearch.bsky.social
about 1 year ago
#ClickFix went from virtually non-existent to the second most common attack vector blocked by #ESET, surpassed only by #phishing. This novel social engineering technique accounted for nearly 8% of all detections in H1 2025. #ESETresearch 1/7
1 4 7
ESET Research
@esetresearch.bsky.social
about 1 year ago
ESET Threat Report H1 2025: #ClickFix attacks surge 500%, SnakeStealer tops infostealer charts, and NFC fraud jumps 35x. Plus, chaos in the ransomware underworld and a new Android adware menace—Kaleidoscope. Dive into the full report: web-assets.esetstatic.com/wls/en/paper... #ESETresearch
0 4 6

Posts are pulled live from Bluesky and cached briefly. Posts with content labels are hidden.