Lure theme
Fake browser update
The oldest ClickFix pretext, and still in service. An overlay claims the browser is out of date and must be updated before the page will load. Where an earlier generation of fake-update pages offered a file to download, the ClickFix version asks for a command to be run instead — which is what lets it walk past the download reputation checks that had made the file version expensive.
- First reported
- 2024-03
- Targets
- Windows · macOS
- Campaigns on record
- 4
The first widely reported ClickFix pages, in March 2024, used exactly this pretext. Fake-update overlays as a delivery pattern are years older; only the paste step is new.
Also reported as Fake Chrome update · Update required lure · Browser out of date overlay · Manual update lure
What a victim sees
A full-page overlay written in the browser's own visual language: the vendor's colours, a rounded card, a version-shaped string, one primary button. The wording is urgent without being alarming — an update is required, the page cannot be displayed, this browser is no longer supported. The button downloads nothing. It swaps the card for a list of keyboard steps described as a manual installation, often justified by a claim that the automatic update has failed and must be finished by hand.
Described rather than shown. This site publishes no screenshots of lure pages and reproduces none of their markup, because a working copy of a fake verification page is a fake verification page regardless of why it was made.
The tell-tale sign
Browsers update themselves, from inside the browser. Chrome, Edge, Firefox and Safari have never shipped an update through a web page, and no browser update has ever needed you to run a command.
The underlying rule is the same for every theme on this site, and it is the one worth remembering: no legitimate website will ever ask you to press Windows+R, to open Terminal, or to paste anything into either one. Why that rule holds.
Campaigns using this lure
Interlock ransomware and FileFix
Status as last assessed: ActiveInterlock has been run against businesses and critical infrastructure in North America and Europe since September 2024. Two ways in are on record: a drive-by download from broken-into websites, or a counterfeit CAPTCHA page whose numbered steps talked the visitor into pasting the clipboard into the Run box — later into a file-manager address bar, the variant called FileFix. Both routes started a PowerShell stage that pulled down a remote access trojan dressed as a browser update or a VPN client installer. The DFIR Report documented a PHP rewrite of that trojan in June 2025, reached through the KongTuke web-inject and calling home over tunnel hostnames. A joint FBI, CISA, HHS and MS-ISAC advisory followed eight days later. Operators then took credentials, moved between hosts over RDP, pushed data to cloud storage, and encrypted virtual machines.
ID 7d2eb0fdFirst seen 2024-09-01Last seen 2025-07-14WindowsRhadamanthys in a fake update lure
Status as last assessed: ActiveFrom the start of October, Huntress recorded a second lure feeding the same steganographic loader. Here the browser was pushed into full screen and dressed up as the blue update splash, animations included, before the viewer was asked to open the Run box and paste a line already sitting on the clipboard. The page source was not obfuscated, carried Russian comments, and posted each interaction to a statistics script, which gave Huntress a urlscan pivot for finding more sites. Five partner incidents between 1 and 17 October used one address for both the mshta stage and the PowerShell behind it, with only the filename rotating; the operator later moved the second-stage domain but kept the address. The payload at the end was Rhadamanthys, not Lumma. A takedown of Rhadamanthys infrastructure was announced on 13 November, yet more sites still served the lure on 19 November.
ID 018c699eFirst seen 2025-10-01Last seen 2025-11-19WindowsMuddyWater deploying Level RMM
Status as last assessed: DormantOver two days in November 2024 the Iranian group Proofpoint calls TA450, known elsewhere as MuddyWater and Mango Sandstorm, mailed staff at 39 or more organisations from an address on a look-alike Microsoft domain it had registered. The message posed as an urgent patch notice. Unusually for this technique there was no web lure at all: the instructions sat in the mail body, telling the reader to open PowerShell with administrator rights and paste in a supplied line. That line pulled down Level, a commercial remote monitoring and management product, which the operators then drove for espionage and data theft rather than deploying custom malware. Israel's national cyber directorate named the tool the next day. Proofpoint had watched the group lean on Atera, PDQ Connect, ScreenConnect and SimpleHelp before, though not Level. Targets clustered in the Gulf, weighted towards finance and government.
ID 14797046First seen 2024-11-13Last seen 2024-11-14WindowsNetSupport RAT via link-free mail
Status as last assessed: ActiveFrom 5 September 2024, Proofpoint saw mail signed "Security Agent" telling recipients that unnamed software on their machine had to be patched, with step-by-step wording for opening a terminal and typing an encoded command themselves. Nothing was attached and there was no link at all, which is why the message read as ordinary correspondence and had little for a mail gateway to catch. Running the command fetched a further script, which in turn pulled down 7-Zip together with a password-protected archive, unpacked it and started NetSupport, a legitimate remote-control product repurposed as a backdoor. Proofpoint notes that variants asking this much of the recipient are probably less productive than the ones that fill the clipboard for them. The sender address at a free German mail provider is the only indicator published for it.
ID 6e742ac5First seen 2024-09-05Last seen 2024-09-05Windows