ClickFix Used in Malvertising Campaign to Target Users

25 Nov 2025

Cybersecurity experts have identified a new malicious campaign called JackFix, which targets users with deceptive advertisements that lead to fake adult sites. The result is a fake Windows Update page that tricks users into executing the ClickFix command.

Campaign Mechanics and Strategies

The JackFix campaign employs the mshta.exe tool to run JavaScript that instructs users to open the Windows Run dialog. By using the ClickFix command, these scripts download a PowerShell script that not only has obfuscation techniques but also includes malicious actions such as anti-analysis garbage code and privilege escalation with -Verb RunAs.

The script creates exceptions for itself in Microsoft Defender, which prevents it from being flagged as a threat. Multiple harmful payloads have been linked to this campaign, including the Rhadamanthys Stealer, Vidar Stealer 2.0, and RedLine Stealer, among others.

Detection and Mitigation Measures

Reports by Huntress indicate the existence of a multi-stage attack chain, using a Stego Loader to hide encrypted shellcode inside PNG images. This method leads to the deployment of further malware such as Lumma and Rhadamanthys.

  • Domains involved include securitysettings[.]live, linked to IP 141.98.80[.]175.
  • Russian developer comments have been found in site iterations.
  • This attack tries to prevent users from escaping by disabling key functions like Escape and F11.

Organizations are recommended to train their employees to spot such fraudulent attempts and block malvertising. Another preventive measure includes disabling the Windows Run box using Registry changes.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7218353
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1637484
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
700945
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
486360
downloads

News and reviews for Desktop Windows

Affordable Antivirus Options for Home Devices

Discover budget-friendly antivirus deals under $30 for 2026 with essential security features.

Read more

Free Script Removes AI Features from Windows 11

A new script disables AI features like Copilot in Windows 11, offering a cleaner interface.

Read more

Spot Fake BSOD: New Threat Hits Hospitality Sector

A social engineering scam uses a Fake BSOD to target European hotels, tricking staff into installing malware via a browser tab.

Read more

GOG's Winter Classics Promo Features Discounts Up to 95%

GOG's Winter Classics Promo offers vintage PC games at up to 95% discount, from 2026-01-06 to 2026-01-20.

Read more

Launch Humble Choice with Sonic Frontiers

Humble Choice unveils January lineup with Sonic Frontiers, Tomb Raider, Hunt: Showdown. Membership grants game codes with benefits, priced at $14.99/month.

Read more

ErrTraffic Malware Utilizes Fake Error Pop-ups to Spread

ErrTraffic is spreading malware via fake pop-ups on compromised sites, affecting multiple OS since 2026-01-07.

Read more

Windows 11 26H1 to Launch on Snapdragon X2 This Spring

Windows 11 26H1 launches exclusively on Snapdragon X2 PCs in spring 2026, enhancing performance and stability. Intel, AMD models retain 25H2.

Read more

First Light: Updated System Requirements Announced

IO Interactive reveals the First Light specs, offering a smoother experience for gaming PCs. Minimum setup supports broad compatibility.

Read more

Splitgate's Rebrand to Arena Reloaded Faces Mixed Responses

1047 Games' Splitgate Arena Reloaded shows lower Steam metrics but retains a dedicated community.

Read more

Norton 360 in 2026: Key Features and User Benefits

In 2026, Norton 360 evolves as a comprehensive cybersecurity suite, offering antivirus, VPN, and identity-theft tracking. Norton remains a trusted choice.

Read more