ClickFix Lure Pushes Trojan Zoom/WebEx Installers

IT Pro Security · High sophistication
Last updated July 30, 2026

Cisco Talos reports a real, financially motivated campaign by a Russian-speaking group (UAT-11795) targeting organizations in the US and Europe. The attackers use a “ClickFix” social-engineering trick to get victims to run a command, which leads to downloading trojanized installers for trusted tools (like Zoom/WebEx) and then stealing credentials and cryptocurrency. The campaign also uses stealthy, memory-only tooling and unusual command-and-control methods to maintain access.

How the Attack Worked

Cisco Talos tracked a financially motivated, Russian-speaking group identified as UAT-11795, active since at least June of last year. The group's initial access method relies on a ClickFix social engineering technique: a webpage entices the user to copy and run a command to "fix" an issue. That command stealthily downloads and executes a remotely hosted weaponized HTA file, which runs an embedded VBScript that drops a batch file into the user's application temporary folder.

From there, the infection chain proceeds to install trojanized installers for legitimate, trusted software such as Zoom, WebEx, MobaXterm, DBeaver, and FaceIT. These fake installers are staged on attacker-controlled domains. Once installed, the campaign deploys previously undocumented tools, including a remote access trojan and a PowerShell-based in-memory implant, to steal credentials, browser data, and cryptocurrency wallet assets. Talos also noted an unusual fallback command-and-control method using a Polygon smart contract, reflecting a high level of sophistication.

Why It Succeeded

The attack succeeds by exploiting trust in everyday workflows. Employees are conditioned to follow on-screen instructions to resolve technical issues, and a prompt to run a command to "fix" a problem does not always register as suspicious. Similarly, requests to reinstall or update common conferencing and remote-access tools like Zoom or WebEx can seem routine, especially for remote and hybrid workers who rely on these tools daily. The use of legitimate, well-known software names as cover makes the trojanized installers more convincing, and reliance on the fact that an installer is signed can create false confidence that it is safe.

What to Watch For

  • Any webpage asking a user to copy and paste a command to run on their computer
  • Instructions to execute scripts or commands that download files from the internet
  • No clear verification that an instruction is coming from the organization's actual IT team
  • Software installers sourced from anywhere other than the official vendor site or approved company portal
  • Unexpected prompts to reinstall or update conferencing or remote-access tools

Building Resistance

Organizations should train staff to treat any copy/paste command request from a website as high risk and to verify such requests through known IT channels before acting. Software installation should be restricted to approved sources, such as a company software portal or vetted vendor sites, with clear guidance to verify download origin when in doubt. Security teams should also avoid treating a signed installer as automatic proof of safety, and should be able to answer where a given binary came from as readily as whether a known vulnerability has been patched. Techniques referenced include T1204.001, T1204.002, and T1656.

Key findings

  • Cisco Talos tracked a Russian-speaking, financially motivated actor as UAT-11795, active since at least June last year.
  • Initial access is obtained via “ClickFix” social engineering that convinces users to run a command, which downloads and executes a weaponized HTA file.
  • The infection chain ultimately installs trojanized installers for legitimate, trusted software (e.g., Zoom, WebEx, MobaXterm, DBeaver, FaceIT).
  • The campaign deploys previously undocumented tools (Starland RAT and a PowerShell-based WLDR in-memory implant) to steal credentials, browser data, and crypto wallet assets.
  • Talos noted an unusual fallback C2 method using a Polygon smart contract.

Who’s being targeted

  • Commonly targeted roles: All employees, Remote/Hybrid workers, IT support/Helpdesk, IT procurement/software asset management, Security operations.
  • Affected industries: Multiple industries (not specified), Organizations using remote/hybrid work tools, Cryptocurrency holders/users.
  • Attack channels: website.
  • Impersonated: Software/support instructions on a web page (ClickFix prompt), Trusted software vendor / legitimate software download page.

Red flags to watch for

  • Any webpage asking you to run a command on your computer is suspicious
  • Instructions to execute scripts/commands that download files from the internet
  • No clear verification that the instruction is coming from your company’s IT team
  • Installer source is not the official vendor site or approved company portal
  • Unexpected prompt to reinstall/update conferencing or remote-access tools
  • Overreliance on “it’s signed” or “it looks official” instead of verifying the download origin
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the ClickFix social engineering technique?

ClickFix entices a user to execute a command shown on a webpage in order to fix a supposed problem, but running it stealthily downloads and executes a weaponized HTA file that begins the infection chain.

Which legitimate software was trojanized in this campaign?

The attackers used trojanized installers for well known tools including Zoom, WebEx, MobaXterm, DBeaver, and FaceIT to steal credentials and cryptocurrency.

Who is behind this campaign?

Cisco Talos tracked a Russian-speaking, financially motivated actor identified as UAT-11795, active since at least June of last year.

Does a signed installer mean the software is safe?

No. Researchers noted that users should not assume a signed installer means a program is safe, since trojanized installers were used to deliver malware in this campaign.

Read the video transcript

Imagine a web page that says: "To continue, copy this command and run it." That’s the ClickFix trap. Cisco Talos saw a group called UAT-11795 use this ClickFix trick: your command secretly pulls down a weaponized HTA file, then installs trojanized Zoom or WebEx that quietly steals passwords and crypto. Here’s the catch: that installer can be signed and look totally legit. The only real tell is where it came from, some random download page, not our software center or the official vendor site. If any site tells you to copy a command or install Zoom, WebEx, or similar from anywhere but our approved sources, stop and send a screenshot to IT using our usual helpdesk channel.

Similar attacks

Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

July 17, 2026