News

Russia's Elite Hackers Adopt Clickfix Social-Engineering Technique

Russia's Top Hackers Embrace Clickfix

A social-engineering technique once primarily associated with financially motivated cybercriminals has now been adopted by Russia's most elite state-sponsored hacking groups, according to recent security research.

Clickfix is a social-engineering method that tricks users into executing malicious commands on their devices, typically through deceptive pop-ups or misleading instructions. This technique has long been popular among lower-tier cybercriminals due to its effectiveness and relatively low technical barrier.

The shift to include Russia's advanced persistent threat (APT) actors marks a notable evolution in the tactics employed by these sophisticated hacking operations, which have historically relied on more complex exploit chains and custom malware.

Security analysts suggest this adoption reflects a broader trend of threat actors borrowing effective techniques from one another, regardless of their sophistication level or objectives.

Sources