Target Industry

Indiscriminate, opportunistic targeting.

Overview

Threat actors have developed a novel method for delivering ransomware by embedding malicious instructions within content designed to be summarised by AI tools. According to research by a threat monitoring vendor, this technique is part of a new social engineering campaign dubbed “ClickFix.” 

Impact

The emergence of the ClickFix attack presents a serious organisational risk, particularly for businesses that use AI tools to process and summarise external content. If malicious instructions embedded in such content are executed, it could result in ransomware infections, operational disruption, and reputational damage. AI systems may inadvertently become conduits for malware, undermining trust in automation and increasing the organisation’s exposure to cyber threats. 

Exploitation

Threat actors exploit AI summarisation tools by embedding malicious instructions in HTML content using CSS obfuscation. These hidden commands, written in natural language, are invisible to humans but readable by AI. By repeating the payload multiple times, attackers overwhelm the AI’s context, causing it to prioritise the malicious input. When summarised, the AI may include harmful commands such as those triggering ransomware via Windows Run, making it an unwitting participant in the attack chain. 

Containment, Mitigations & Remediations

To mitigate the ClickFix attack, organisations should implement HTML preprocessing to strip suspicious CSS attributes such as zero-width characters and hidden text. AI input should be sanitised to remove repeated patterns and detect natural language commands that resemble system instructions. Security teams should deploy pattern recognition tools to identify known payload formats and enforce enterprise-level policies that scan inbound content before it reaches AI systems. Additionally, staff should be trained to critically assess AI-generated outputs and avoid executing suggested commands without verification. 

Threat Landscape

The ClickFix attack marks a shift in the threat landscape, where AI tools are being targeted as part of the attack chain. By exploiting AI summarisation through hidden prompt injection, threat actors move beyond traditional malware delivery to more subtle, trust-based social engineering. This expands the attack surface and challenges defenders to secure not just endpoints, but also the AI systems integrated into everyday workflows. 

Threat Group

At the time of writing, no specific threat actor group had been publicly attributed to the ClickFix attack campaign. However, several state-sponsored and cybercriminal groups have since been observed using the technique in active campaigns. 

Further Information

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content