Threat IntelligenceSep 8, 2026
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
ClickFix campaigns leverage legitimate services for persistent access via social engineering.
Summary
Two distinct campaigns, dubbed ClickFix, have been observed abusing legitimate cloud services to gain persistent access within victim environments. These attacks rely on social engineering tactics to trick users into executing malicious payloads, which then establish a foothold using cloud-based infrastructure. The methods employed highlight a growing trend of threat actors leveraging trusted services to evade detection and maintain access.
Entities
ClickFix (campaign)