Validin will be at Black Hat 2026, Booth #6200 — schedule time to meet with us for an enterprise demo or an online meeting

ClickFix

Aliases: ClearFake • ClickFix is a fake browser update malware that is distributed through malicious WordPress plugins and targets visitors of compromised websites.
Profile
Malicious
Category
Malware
Threat Type
Unknown
Country
clickfix
Profile Key
The profile key is a unique identifier for this threat actor. It can be used to query the Validin APIs as the threat_key for information about this threat actor.
Last Updated
Summary
Indicator Activity
Loading activity...
No indicators recorded yet.
Description

ClickFix, also known as ClearFake, is a fake browser update malware that is distributed through malicious WordPress plugins. These plugins inject JavaScript into websites, which then displays fake browser update prompts to visitors. The malware leverages social engineering to trick users into downloading and executing malicious payloads, such as remote access trojans and information stealers like Vidar and Lumma. ClickFix has been observed in the wild since 2023 and is often spread through compromised websites with stolen administrator credentials.

Aliases (1)
ClearFake
Alias
Targets (2)
Windows
Target
Website visitors
Target
External Sources