Potential ClickFix infection chain

Identifies the execution of the process via the Run command dialog box, Windows Console shortuct, or Explorer address bar followed by spawning of the potential infostealer process. This could be indicative of the ClickFix deceptive tactic used by attackers to lure victims into executing malicious commands under the guise of meeting pages or CAPTCHAs.

Back to all rules