ctipilot.ch
← Back to Weekly 2026-W26
NOTABLEresearch

Research: ClickFix matured into a productised malware-as-a-service supply chain

discovered 2026-06-22 00:14 UTCrun 2026-W25-0aacfe652 sourcesmulti-source

A second cross-day research thread: the ClickFix technique — fake browser/update dialogues that trick users into pasting attacker PowerShell — has industrialised. Sekoia documented ErrTraffic, a ClickFix Malware-as-a-Service framework that resolves its C2 through the Polygon blockchain (Sekoia, 2026-06-17; daily 06-17), and Huntress detailed the Potemkin loader delivering RMMProject RAT through a ClickFix chain that also bypasses Chromium App-Bound Encryption (Huntress, 2026-06-17; daily 06-17). ErrTraffic also surfaced as one of the SocGholish-adjacent clusters still operating after the Operation Endgame takedown (§ 8). The pattern for defenders: ClickFix is now a delivery channel with multiple competing operators and resilient C2, so user-paste-to-PowerShell detection (clipboard-sourced powershell.exe/mshta.exe invocations, RunMRU artefacts) is worth promoting from awareness training to a standing hunt.

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.