CrowdStrike Explains ClickFix Attacks and How Its Defenses Disrupt Them

· Original article ↗

Summary

ClickFix lures users into pasting commands from deceptive webpages into trusted system tools, enabling malware and credential theft. CrowdStrike describes activity attributed to STARDUST CHOLLIMA and VOODOO BEAR and outlines layered defenses.

Key points

  • Fake meeting errors, CAPTCHAs, or other webpage prompts persuade users to copy commands into tools such as Windows Run or PowerShell; the commands can retrieve or execute further payloads.
  • Follow-on activity can include malware deployment, credential theft, persistence, command and control, data theft, and broader access to an environment.
  • CrowdStrike reports a July 2026 case likely involving STARDUST CHOLLIMA, in which a fake video-meeting issue led to a PowerShell- and VBScript-based chain deploying GeniexLoader and GeniexRAT.
  • In May and June 2026, CrowdStrike detected likely VOODOO BEAR intrusions using fake CAPTCHAs on compromised Ukrainian websites to deliver a VBScript payload via PowerShell.
  • CrowdStrike’s 2026 Global Threat Report recorded a 563% increase in incidents involving fake CAPTCHA lures in 2025.
  • The article recommends layered controls across browser activity, endpoint execution, identity, and security operations to detect or disrupt different stages of the attack.

Article Details

Topic
ClickFix social engineering and CrowdStrike defenses against its browser-to-endpoint attack chain

MITRE ATT&CK

Threat Actors

Malware

Vendors

Products

Countries

Industries

Related Articles