TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Huntress

That “Friendly” Prompt is ClickFix

2026-03-25 · Read original ↗

ATT&CK techniques detected

8 predictions
T1204.001Malicious Link
96%
“” says nick roddy, security operations analyst at huntress. this also helps explain why clickfix made up over 50 % of all malware loader activity, according to the huntress 2026 cyber threat report. you ' ve probably been through plenty of security awareness trainings, so you ’ r…”
T1204.004Malicious Copy and Paste
94%
“tripping up so many end users. the attack that feels like help clickfix works by tricking users into executing malicious commands on their own systems. rather than dropping malware through a link or attachment, attackers manipulate victims into doing the work themselves by copyin…”
T1204.004Malicious Copy and Paste
79%
“that “ friendly ” prompt is clickfix cybercrime isn ’ t the chaotic mess of random attacks people still imagine. it ’ s a booming global economy, projected to cost the world $ 12. 2 trillion annually by 2031. social engineering is one of the main engines driving that growth. atta…”
T1204.004Malicious Copy and Paste
74%
“” says nick roddy, security operations analyst at huntress. this also helps explain why clickfix made up over 50 % of all malware loader activity, according to the huntress 2026 cyber threat report. you ' ve probably been through plenty of security awareness trainings, so you ’ r…”
T1204.004Malicious Copy and Paste
71%
“from the truth. here are two types of attack paths that started when a human fell for clickfix prompts : figure 3 : example of lummac2 infostealer compromise after a clickfix infection figure 4 : example of an intrusion timeline after a clickfix infection why resilience is a winn…”
T1204.001Malicious Link
61%
“tripping up so many end users. the attack that feels like help clickfix works by tricking users into executing malicious commands on their own systems. rather than dropping malware through a link or attachment, attackers manipulate victims into doing the work themselves by copyin…”
T1566.002Spearphishing Link
41%
“that “ friendly ” prompt is clickfix cybercrime isn ’ t the chaotic mess of random attacks people still imagine. it ’ s a booming global economy, projected to cost the world $ 12. 2 trillion annually by 2031. social engineering is one of the main engines driving that growth. atta…”
T1204.001Malicious Link
40%
“that “ friendly ” prompt is clickfix cybercrime isn ’ t the chaotic mess of random attacks people still imagine. it ’ s a booming global economy, projected to cost the world $ 12. 2 trillion annually by 2031. social engineering is one of the main engines driving that growth. atta…”

Summary

That "friendly" prompt is a ClickFix scam. Learn about this advanced social engineering tactic that tricks users into running malicious code on their own systems, and why security resilience is your winning bet.