Target Industry
Indiscriminate, opportunistic targeting.
Overview
Threat actors have developed a novel method for delivering ransomware by embedding malicious instructions within content designed to be summarised by AI tools. According to research by a threat monitoring vendor, this technique is part of a new social engineering campaign dubbed “ClickFix.”
Impact
The emergence of the ClickFix attack presents a serious organisational risk, particularly for businesses that use AI tools to process and summarise external content. If malicious instructions embedded in such content are executed, it could result in ransomware infections, operational disruption, and reputational damage. AI systems may inadvertently become conduits for malware, undermining trust in automation and increasing the organisation’s exposure to cyber threats.
Exploitation
Threat actors exploit AI summarisation tools by embedding malicious instructions in HTML content using CSS obfuscation. These hidden commands, written in natural language, are invisible to humans but readable by AI. By repeating the payload multiple times, attackers overwhelm the AI’s context, causing it to prioritise the malicious input. When summarised, the AI may include harmful commands such as those triggering ransomware via Windows Run, making it an unwitting participant in the attack chain.
Containment, Mitigations & Remediations
To mitigate the ClickFix attack, organisations should implement HTML preprocessing to strip suspicious CSS attributes such as zero-width characters and hidden text. AI input should be sanitised to remove repeated patterns and detect natural language commands that resemble system instructions. Security teams should deploy pattern recognition tools to identify known payload formats and enforce enterprise-level policies that scan inbound content before it reaches AI systems. Additionally, staff should be trained to critically assess AI-generated outputs and avoid executing suggested commands without verification.
Threat Landscape
The ClickFix attack marks a shift in the threat landscape, where AI tools are being targeted as part of the attack chain. By exploiting AI summarisation through hidden prompt injection, threat actors move beyond traditional malware delivery to more subtle, trust-based social engineering. This expands the attack surface and challenges defenders to secure not just endpoints, but also the AI systems integrated into everyday workflows.
Threat Group
At the time of writing, no specific threat actor group had been publicly attributed to the ClickFix attack campaign. However, several state-sponsored and cybercriminal groups have since been observed using the technique in active campaigns.
Further Information
Intelligence Terminology Yardstick













