Advertisement
  • Safe Mode

ClickFix and the social engineering of routine

It starts with a fake error message. It ends with a pasted command. ClickFix has become one of the most reliable ways for attackers to get an initial foothold — first adopted by criminal groups, now used by state-linked actors like APT28 and Lazarus Group.

This week, Greg is joined by John Hammond, Principal Security Researcher at Huntress, who helped identify and name the technique and has tracked its evolution for the past three years. They dig into why ClickFix still drives an estimated 20+ incidents a day at Huntress even after law enforcement disrupted major infostealer infrastructure like LumaStealer, how the technique has splintered into variants like FileFix and “consent fix” targeting Microsoft 365 and browser-stored credentials, and how attackers are now smuggling payloads inside images to slip past endpoint defenses. John walks through a real incident where a single pasted command led to 11 compromised devices, explains why he still believes security awareness training — not just tooling — is the best defense, and makes the case that the browser itself has become the blurriest and most under-protected boundary between endpoint and identity security.

The conversation also turns to the npm/Axios supply chain attacks, where operators built fake Slack communities and fabricated employee personas to earn open-source maintainers’ trust before compromising their packages — and what, if anything, can technically guard against a threat that’s fundamentally social.

In our reporter chat, Greg talks with Derek Johnson about the Supreme Court deciding against the Trump administration’s push for changes to mail-in ballots.

Follow John on Youtube: https://www.youtube.com/@_JohnHammond

Weekly

Safe Mode

Every week we break down the most pressing issues in technology, provide you with the knowledge and tools to stay ahead of the latest threats and take you behind the scenes of the biggest stories in cyberspace.

Advertisement