ClickFix attack involving fake Windows BSOD/Update screens

  • ClickFix is a social-engineering malware delivery technique that tricks victims into manually running malicious commands on their own Windows PC.
  • The attack does not rely on automatic exploitation or drive-by downloads — instead, users are manipulated into infecting themselves.

This Latest Variant: Fake Windows BSOD/Update

  • Phishing emails (e.g., pretending to be about a Booking.com reservation) lead users to malicious web pages.
  • Once on the page, users are shown a convincingly spoofed Windows “Blue Screen of Death” or “Windows Update” screen in full-screen mode.
  • This fake screen instructs the user to perform what appears to be a normal fix — opening the Run dialog (Win+R), pasting a command, and hitting Enter.

How It Actually Infects You

  • The command the page tells the user to run typically uses legitimate Windows tools like mshta.exe to pull and execute malicious scripts.
  • These scripts then fetch additional malware — often infostealers (like LummaC2 or Rhadamanthys) — and may hide their code using steganography inside image files to evade detection.
  • Some campaigns even use fake adult sites or other enticing lures to get victims to the malicious page in the first place.

Why This Is Dangerous

  • Because it looks like a trusted system screen, users may not realize they are being tricked.
  • Legitimate Windows updates never ask you to paste commands from a browser into your system.
  • The technique relies on psychology and deception — and security tools can miss it entirely if the user complies.

How to Protect Yourself

  • Don’t run any commands copied from a webpage or email prompt. Legitimate software updates don’t work this way.
  • Keep Windows updates inside the official Settings app or other trusted channels.
  • Use reputable antivirus and endpoint security tools to detect unusual scripting behavior.
  • Training and awareness are key: users should recognize red flags like urgent “fix it” demands that ask them to run code.