Aliases: ClearFake • ClickFix is a fake browser update malware that is distributed through malicious WordPress plugins and targets visitors of compromised websites.
Profile
Malicious
Category
Malware
Threat Type
Unknown
Country
clickfix
Profile Key
The profile key is a unique identifier for this threat actor. It can be used to query the Validin APIs as the threat_key for information about this threat actor.
2026-09-28T18:19:07Z
Last Updated
Summary
Description

ClickFix, also known as ClearFake, is a fake browser update malware that is distributed through malicious WordPress plugins. These plugins inject JavaScript into websites, which then displays fake browser update prompts to visitors. The malware leverages social engineering to trick users into downloading and executing malicious payloads, such as remote access trojans and information stealers like Vidar and Lumma. ClickFix has been observed in the wild since 2023 and is often spread through compromised websites with stolen administrator credentials.

Aliases (1)
ClearFake
Alias
Targets (2)
Windows
Target
Website visitors
Target
External Sources