ClickFix Scams Use Fake Verification Pages to Deploy Multiple Malware Families
Threat actors are weaponizing users' trust in recognizable brands like Google and Cloudflare by presenting convincing fake verification pages that prompt victims to manually execute malicious commands. This 'ClickFix' technique bypasses many traditional security controls because the user themselves becomes the execution vector, making endpoint defenses less effective. The abuse of legitimate infrastructure — such as Cloudflare R2 buckets and repurchased domains — helps attackers evade reputation-based filtering and detection tools. This campaign matters because it demonstrates that social engineering continues to outpace technical defenses, and a single deceived user can result in the deployment of stealers, RATs, and multiple other malware families simultaneously.
Tactical Insight
Immediate actions
- Train all users to recognize that no legitimate Google or Cloudflare verification process will ever ask them to copy and paste commands into a terminal or Run dialog.
- Block execution of PowerShell, cmd, and scripting engines from non-administrative user contexts using application control policies (e.g., AppLocker or Windows Defender Application Control).
- Implement DNS filtering and web proxy policies to flag or block newly registered and recently repurchased domains.
Long-term improvements
- Establish a regular security awareness training cadence that includes phishing and social engineering simulations specifically covering ClickFix-style lures.
- Enforce the principle of least privilege so standard users cannot execute commands or install software even if they are deceived into attempting it.
- Maintain an up-to-date allowlist of trusted cloud storage domains and scrutinize unexpected outbound connections to services like Cloudflare R2.
Detection measures
- Deploy endpoint detection and response (EDR) tooling with behavioral rules that alert on unusual parent-child process relationships, such as a browser spawning PowerShell or cmd.
- Enable SIEM correlation rules to detect clipboard-based command execution patterns and bulk credential access activity indicative of stealers like StealC.
- Monitor for outbound connections to Cloudflare R2 buckets and other cloud object storage services that are not part of approved business workflows.