Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
initial-access-methodphishing-campaign-intelligenceloader-delivery-mechanismremote-access-implant

ClickFix Social Engineering Drives Multiple Malware and Ransomware Intrusions

Updated 3mo agoFirst seen Mar 17, 20263 sources

Attackers are increasingly using ClickFix fake CAPTCHA and verification lures on compromised websites to trick users into manually executing malicious commands, turning social engineering into a scalable initial-access method. LeakNet adopted the technique to reduce reliance on stolen credentials and initial access brokers, using hacked sites to deliver a staged Deno-based in-memory loader before following a repeatable post-exploitation sequence that can end in ransomware deployment. Separately, the ZPHP campaign used similar fake Cloudflare Turnstile-style prompts against U.S. SLTT organizations to deliver Remcos RAT, with hidden JavaScript on compromised sites selectively replacing page content with attacker-controlled instructions for Windows users.

The reporting indicates a broader shift in which ClickFix is no longer tied to a single actor or payload, but is being reused across financially motivated and malware-delivery operations because it is cheap, effective, and difficult for users to recognize as malicious. One additional roundup reference points to Termite ransomware and CastleRAT activity linked to ClickFix, reinforcing that the technique is spreading across campaigns, but it does not provide enough detail to treat that activity as the same incident as LeakNet or ZPHP. This is not fluff: the material contains concrete threat intelligence on active intrusion methods, victim targeting, malware delivery chains, and operational tradecraft relevant to enterprise defense.

Share:
ClickFix Social Engineering Drives Multiple Malware and Ransomware Intrusions
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 17, 20263mo ago

CIS publishes analysis of ZPHP ClickFix campaign and SLTT impact

CIS released technical details on the ZPHP campaign, describing a kill chain involving malicious JavaScript, mshta.exe, an HTA file, PowerShell, a large ZIP archive, and DLL sideloading with in-memory decryption to deploy Remcos RAT. The organization said it had linked the activity to multiple SLTT incidents and observed substantial detection and blocking volume across its monitoring services.

ReliaQuest links separate Teams phishing attempt to same LeakNet loader chain

ReliaQuest said a distinct Microsoft Teams phishing intrusion attempt resulted in the same Deno-based loader and similar post-compromise activity seen in the ClickFix intrusions. This indicated LeakNet was using multiple initial access methods that converged on the same tooling and attack sequence.

LeakNet adopts ClickFix via compromised websites for initial access

ReliaQuest reported that LeakNet shifted from relying on stolen credentials from initial access brokers to using ClickFix social engineering delivered through hacked websites. Victims were prompted by fake CAPTCHA pages to run a malicious msiexec.exe command, leading to a Deno-based in-memory loader and a repeatable post-exploitation chain ending in data theft and encryption.

Jan 1, 20266mo ago

ZPHP campaign targets U.S. SLTT organizations with Remcos RAT

In 2026, CIS observed an ongoing ZPHP malware campaign affecting U.S. State, Local, Tribal, and Territorial government organizations. The activity used compromised websites, fake Cloudflare Turnstile CAPTCHA pages, and ClickFix lures to trick users into executing malicious commands that ultimately deployed Remcos RAT.

Nov 1, 20242y ago

LeakNet ransomware operation emerges

LeakNet emerged in November 2024 and described itself as a "digital watchdog." Reporting cited by ReliaQuest also noted the group has targeted industrial entities, according to Dragos.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Affected products
6 linked
PostgresqlNodejsWindowsPowershellPostgresqlNode.Js
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.