How ClickFix Attacks Work—and How CrowdStrike Says It Disrupts Them

· Original article ↗

Summary

ClickFix tricks users into running commands from deceptive webpages. CrowdStrike describes activity attributed to STARDUST CHOLLIMA and VOODOO BEAR, and outlines browser, endpoint, identity, and monitoring defenses.

Key points

  • ClickFix uses fake meeting errors, CAPTCHAs, or other prompts to persuade users to paste commands into trusted tools such as Windows Run or PowerShell.
  • The commands can launch scripts that download malware, steal credentials, establish persistence, or enable further access.
  • CrowdStrike says STARDUST CHOLLIMA likely used a fake video-conferencing site in July 2026 to deliver a PowerShell- and VBScript-based infection involving GeniexLoader and GeniexRAT.
  • CrowdStrike attributes fake-CAPTCHA intrusions affecting organizations in France, the United States, and Canada to likely VOODOO BEAR activity using compromised Ukrainian websites.
  • CrowdStrike's 2026 Global Threat Report documented a 563% increase in incidents involving fake CAPTCHA lures in 2025.
  • The article recommends layered defenses across browsers, endpoints, identity, and security monitoring to disrupt execution, credential abuse, and follow-on activity.