Explosion
Russia's Elite Hackers Adopt ClickFix to Hijack Devices
Technology

Russia’s Elite Hackers Adopt ClickFix to Hijack Devices

Daniel ParkBy Daniel Park·

Russia’s most advanced state-sponsored hacking group has begun using ClickFix, a social-engineering tactic that tricks people into harming their own devices. This technique previously mostly belonged to financially motivated cybercriminals, according to a recent report by Ars Technica.

What Is ClickFix?

ClickFix is a straightforward attack method. You might visit a website or open a document, and suddenly, a fake error message appears. It tells you something’s wrong. To “fix” it, you’re instructed to copy a command and paste it into your computer’s terminal or run dialog. That command installs malware. Imagine a mechanic giving you a wrench and guiding you to take apart your own engine—only to have your car drive itself to a chop shop.

This technique doesn’t need software exploits or zero-day vulnerabilities. It simply tricks you into doing the attacker’s work, which explains why it’s so effective and why it has spread quickly among criminal hackers over the last couple of years.

Sandworm Enters the ClickFix Game

The group now using ClickFix is Sandworm, a unit of Russia’s GRU military intelligence. Sandworm has been behind some of the most destructive cyberattacks in history, including the NotPetya malware that caused around $10 billion in global damages in 2017 and multiple attacks on Ukraine’s power grid.

Until now, ClickFix was mainly a tool for criminal hackers aiming to steal banking information or deliver ransomware. Sandworm’s use of this technique marks an important shift: when nation-state actors with extensive resources start borrowing tactics from the criminal world, it shows those tactics are genuinely effective.

Security researchers tracking this campaign find that Sandworm seems to be using ClickFix as an initial access method—a way to gain a foothold on a target’s machine before deploying more advanced tools. The targets, consistent with Sandworm’s history, appear to be government and infrastructure organizations, rather than everyday consumers.

Why State Hackers Are Going Low-Tech

This trend makes sense. Developing sophisticated technical exploits is costly, and they’re easy to burn through once patched. As software companies enhance their security, deploying these exploits becomes tougher. Social engineering, on the other hand, exploits the human factor, which doesn’t receive security patches.

This is why email phishing (fake messages aimed at stealing information or delivering malware) continues to thrive, despite years of awareness campaigns. The technique works because it plays on trust and urgency—two factors that no software can fix.

By The Numbers: Sandworm & ClickFix
Metric Detail
Sandworm origin Russia’s GRU military intelligence
NotPetya damages (2017) ~$10 billion globally
ClickFix origin Financially motivated criminal hackers
Attack method Fake error messages prompt users to run malicious commands
Technical exploits required Zero — relies entirely on user action

What This Means

For most people, Sandworm’s main targets—government agencies, military contractors, and critical infrastructure—don’t directly affect your life. Yet, there are two reasons this still matters.

First, techniques developed by elite groups often trickle down. Once criminal hackers notice state actors using ClickFix effectively, expect more refined and convincing ClickFix campaigns aimed at regular folks’ banking credentials and personal data.

Second, this serves as a reminder of what to watch for. If a webpage, document, or pop-up ever asks you to open your command prompt and paste something in, stop right there. No legitimate software update or customer support process will ever ask you to do that. Period.

This ties into a broader wave of social-engineering scams. CNET recently reported on scammers using FaceTime calls to impersonate bank representatives, pressuring iPhone users to share account credentials. The common thread here is that attackers increasingly rely on your actions instead of technical exploits. CNET has the full breakdown of the FaceTime banking scam here.

Community Reaction

“ClickFix works because it makes the user feel like they’re solving a problem. The moment someone thinks they’re being helpful, their guard drops completely.”

— u/sec_eng_throwaway, r/netsec

“The scariest part isn’t Sandworm using it. It’s that this technique requires literally no hacking skill to copy. Anyone can run these campaigns now.”

— YouTube comment on a Seytonic video covering the Sandworm report

What To Watch

  • Escalation in targets: Security researchers will keep an eye on whether Sandworm extends its ClickFix campaigns beyond government and infrastructure as the technique proves effective.
  • Criminal copycat campaigns: Expect security firms to report a rise in ClickFix attacks targeting consumers in the coming months, particularly those looking for software cracks or troubleshooting guides.
  • Platform responses: Browser makers like Google and Mozilla might speed up warnings or blocks on pages prompting users to copy terminal commands—a countermeasure that’s feasible but not widely implemented yet.
  • Full Sandworm campaign analysis: Threat intelligence firms tracking this campaign are set to publish more detailed technical breakdowns. Ars Technica has ongoing coverage of the Sandworm ClickFix story.
Daniel Park

Daniel Park

Daniel Park covers AI, cloud infrastructure, and enterprise software for Explosion.com. A former software engineer who transitioned to technology journalism 5 years ago, Daniel brings technical depth to his reporting on artificial intelligence, startup funding rounds, and the companies building the future of computing. He breaks down complex AI developments and business strategies into clear, actionable insights for readers who want to understand how technology is reshaping industries.