Skip to main content
← Back to Demos
Script Injection intermediate · 15 min

ClickFix HTML Lure with Browser-Assembled Payload (Atomic Stealer Campaign Pattern)

On August 5, 2026, Microsoft Threat Intelligence detailed a macOS ClickFix campaign whose 250+ front-end domains fingerprint visitors — platform string, screen/window dimensions, WebGL signals — before serving a fake software download, hiding the lure from crawlers and sandboxes. The analyzed chain ends in Atomic Stealer (AMOS), an infostealer that harvests credentials, browser data, authentication stores and crypto wallets after victims paste an obfuscated Terminal command into a fake CAPTCHA or update prompt. ClickFix lures are HTML pages that shift payload execution out of the browser onto the victim's own machine: no exploit, no attachment — the user becomes the delivery mechanism. This demo ships a malicious HTML page in the same shape: a fake "document portal" invoice page whose JavaScript assembles a base64 payload blob in the browser and auto-downloads it as invoice.sh (a benign placeholder that only opens the calculator — safe to run anywhere), exactly the smuggling pattern ClickFix operators use. The clean twin is the sanitized static page. MetaDefender Deep CDR inspects and reconstructs the HTML, stripping scripts, event handlers and embedded payloads so the lure arrives as a harmless static page — the same treatment that neutralizes ClickFix and HTML-smuggling lures before they reach macOS, Windows and Linux endpoints.

Attack Technique

ClickFix HTML smuggling lure with paste-command payload (T1027.006)

MITRE ATT&CK

T1027.006 ↗

Platforms

linuxwindows

File Types

.docx

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---