Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
initial-access-methodloader-delivery-mechanismransomware-group-operation

ClickFix Social Engineering Campaigns Expand Malware and Ransomware Delivery

Updated 3mo agoFirst seen Mar 19, 20265 sources

Researchers reported continued expansion of ClickFix as an initial-access technique, with attackers using fake CAPTCHA or verification pages to trick users into executing clipboard-delivered commands on Windows systems. In one campaign, LeakNet shifted away from relying on initial access brokers and instead used compromised legitimate websites hosting fake Cloudflare Turnstile checks to broaden victim acquisition and reduce network-based detection. ReliaQuest linked the activity to LeakNet through overlapping infrastructure and consistent TTPs, and noted the group paired ClickFix with a stealthy, memory-resident loader built on the Deno JavaScript runtime to support ransomware operations.

A separate ClickFix campaign analyzed by Atos used the same user-executed command pattern to map attacker-controlled network drives with net use, then download a trojanized but legitimately signed WorkFlowy application whose modified asar archive executed malicious code in the Node.js main process with the logged-in user’s privileges. Other reporting on Hive0163 also identified ClickFix as one of several initial-access methods used in Interlock ransomware intrusions, although that article focused primarily on the group’s likely AI-generated Slopoly malware rather than a specific ClickFix incident. Reporting on Operation Covert Access in Argentina’s judicial sector was unrelated, describing spear-phishing with fake court documents to deliver COVERT RAT via a different intrusion chain.

Share:
ClickFix Social Engineering Campaigns Expand Malware and Ransomware Delivery
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Mar 18, 20263mo ago

ReliaQuest attributes expanded ClickFix and Deno activity to LeakNet

ReliaQuest reported with high confidence that LeakNet was behind an expanded campaign using ClickFix lures and a stealthy Deno-based in-memory loader. The attribution was based on overlapping infrastructure and consistent tactics, techniques, and procedures observed across multiple incidents.

Atos identifies ClickFix campaign mapping attacker-controlled drives

Atos researchers identified a new ClickFix campaign that used fake CAPTCHA pages to trick Windows users into running hidden commands through the Run dialog. The attack mapped a remote drive with the native net use command and delivered a trojanized WorkFlowy application that communicated with the command-and-control domain cloudflare.report.

LeakNet shifts to self-delivered ClickFix and Teams phishing campaigns

By March 2026, LeakNet had expanded beyond relying mainly on initial access brokers and began using ClickFix lures on compromised websites, and in at least one case Microsoft Teams phishing, to gain access directly. The updated intrusion chain used a Deno-based in-memory loader and a consistent post-exploitation sequence including jli.dll sideloading, klist, PsExec, and exfiltration to cloud services.

Mar 16, 20263mo ago

IBM publicly reports Slopoly and links Hive0163 to Interlock activity

IBM X-Force disclosed its findings on Slopoly on March 16, 2026, describing it as likely AI-generated malware used by Hive0163 in a ransomware intrusion. The report also linked Hive0163 to Interlock ransomware operations, custom tooling, malvertising, and possible cooperation with initial access brokers, and published indicators including the domain plurfestivalgalaxy[.]com.

Jan 1, 20266mo ago

Hive0163 deploys likely AI-generated Slopoly malware

During the same early-2026 live incident, Hive0163 deployed Slopoly, a custom command-and-control client that IBM X-Force assessed as likely AI-generated. IBM cited traits such as extensive comments, consistent error handling, clearly named variables, and an unused jitter function in support of that assessment.

Hive0163 launches intrusion via ClickFix social engineering

In early 2026, a Hive0163 intrusion began with a ClickFix social engineering attack that tricked a user into running a malicious PowerShell command. The attackers then deployed NodeSnake, InterlockRAT, Slopoly, and post-exploitation tools including AzCopy and Advanced IP Scanner.

Dec 1, 20242y ago

LeakNet ransomware first observed

LeakNet was first observed as an emerging ransomware operator in late 2024. Early reporting described it as a relatively low-volume operation before its later expansion in scale and tradecraft.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

24 LINKEDOpen in app
Threat actors
2 linked
Affected products
5 linked
PsexecPowershellWindows InstallerWindowsLinkedin
Organizations
12 linked
CloudflareMicrosoft CorporationReliaQuestAmazon Web ServicesLinkedinPalo Alto NetworksInternational Business MachinesXOracleAtosGoogleFunRoutine Inc.
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.