CrowdStrike Explains ClickFix Attacks and How Its Defenses Disrupt Them

Summary
ClickFix lures users into pasting commands from deceptive webpages into trusted system tools, enabling malware and credential theft. CrowdStrike describes activity attributed to STARDUST CHOLLIMA and VOODOO BEAR and outlines layered defenses.
Key points
- Fake meeting errors, CAPTCHAs, or other webpage prompts persuade users to copy commands into tools such as Windows Run or PowerShell; the commands can retrieve or execute further payloads.
- Follow-on activity can include malware deployment, credential theft, persistence, command and control, data theft, and broader access to an environment.
- CrowdStrike reports a July 2026 case likely involving STARDUST CHOLLIMA, in which a fake video-meeting issue led to a PowerShell- and VBScript-based chain deploying GeniexLoader and GeniexRAT.
- In May and June 2026, CrowdStrike detected likely VOODOO BEAR intrusions using fake CAPTCHAs on compromised Ukrainian websites to deliver a VBScript payload via PowerShell.
- CrowdStrike’s 2026 Global Threat Report recorded a 563% increase in incidents involving fake CAPTCHA lures in 2025.
- The article recommends layered controls across browser activity, endpoint execution, identity, and security operations to detect or disrupt different stages of the attack.
Article Details
- Topic
- ClickFix social engineering and CrowdStrike defenses against its browser-to-endpoint attack chain
MITRE ATT&CK
T1059.001 · PowerShellObserved ClickFix infection chains used PowerShell commands to download or execute payloads.T1059.005 · Visual BasicThe described infection chains used VBScript payloads.T1204.004 · Malicious Copy and PasteClickFix lures users into copying and pasting malicious commands into operating system utilities.
Threat Actors
Malware
GeniexLoaderRunning that command triggered a PowerShell- and VBScript-based infection chain that deployed two previously unknown malware families: GeniexLoader and GeniexRAT.GeniexRATRunning that command triggered a PowerShell- and VBScript-based infection chain that deployed two previously unknown malware families: GeniexLoader and GeniexRAT.
Vendors
Products
Falcon Adversary OverWatchFalcon CompleteAnd across the entire environment, CrowdStrike Falcon® Adversary OverWatch™ and Falcon Complete add continuous threat hunting, investigation, containment, and remediation.Falcon Identity Threat ProtectionFalcon Insight XDRFalcon Next-Gen SIEMFalcon Platform IOAs Arrive in Falcon Next-Gen SIEM to Identify New ThreatsFalcon platformNew Claude Integration Brings Audit Data into the Falcon PlatformFalcon PreventFalcon Seraphic Enterprise BrowserBefore execution: Falcon Seraphic Enterprise Browser provides visibility and enforcement inside the browser.
Countries
Canadaaffecting employees believed to be Ukrainian at organizations in France, the United States, and Canada.Francedetected likely VOODOO BEAR intrusions affecting employees believed to be Ukrainian at organizations in France, the United States, and Canada.UkraineUnited StatesVOODOO BEAR intrusions affecting employees believed to be Ukrainian at organizations in France, the United States, and Canada.
Industries
AgricultureBEAR activity, including websites of diverse Ukrainian entities (such as local government, energy, agriculture, and logistics entities) likely compromised to serve fake CAPTCHAs.Energyin VOODOO BEAR activity, including websites of diverse Ukrainian entities (such as local government, energy, agriculture, and logistics entities) likely compromised to serve fake CAPTCHAs.Financial ServicesIn July 2026, STARDUST CHOLLIMA very likely targeted an employee at a financial services entity using infrastructure masquerading as a video conferencing site.local governmentdiversity in VOODOO BEAR activity, including websites of diverse Ukrainian entities (such as local government, energy, agriculture, and logistics entities) likely compromised to serve fake CAPTCHAs.logisticsincluding websites of diverse Ukrainian entities (such as local government, energy, agriculture, and logistics entities) likely compromised to serve fake CAPTCHAs.