Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution

Alerts on explorer.exe child process launches with clipboard markers and anti-bot/CAPTCHA-related wording indicating ClickFix/FileFix execution.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
montysecurity, Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-11-19
Updated
2026-07-30

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags suspicious Windows process executions initiated from explorer.exe where the command line contains a clipboard-manipulation marker (#) and includes terms commonly associated with CAPTCHA or anti-bot prompts (for example, captcha, challenge, verification, robot). Attackers use social engineering to trick users into pasting clipboard contents into UI elements like the Run dialog or Explorer address bar, often resulting in execution of attacker-supplied commands. It relies on process creation telemetry capturing the parent process path, the full command line, and keyword matches within that command line.

Related detections9 linkedT1204.001 — drag to rearrange
macOS Script Editor Spawns Suspicious Command-Line Interpreters
Suspicious Script Interpreter Spawned by Explorer via ClickFix Run Dialog (via process_creation)
Malicious Edge Abuse for Payload Download via Console (via process_creation)
Suspicious Masqueraded Windows Update Python Script Execution
ClickFix Pastejacking via Script Interpreter Command in Run Dialog MRU (via registry_set)
Obfuscated Edge/Chrome Headless Feature Abuse for Payload Download (via process_creation)
Suspicious cscript Execution of JavaScript Spawned by PowerShell
Suspicious Ukraine-Themed LNK Lure Files Dropped (via file_event)
Suspicious Renamed MySQL Binary Executed from Temp via ClickFix (via process_creation)
Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Pivot detection · T1204.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.