STATUS: ACTIVE
Social Engineering

XWorm and ClickFix

The ClickFix social-engineering model and its association with XWorm distribution.

AUTHOR: Threat Intelligence Research TeamUPDATED: 2026-10-04VERIFIED: 2026-10-04

ClickFix is a social-engineering model where visitors are shown a fake verification, error, or instruction screen and persuaded to perform an action that results in malicious code execution. Microsoft associates XWorm with ClickFix campaigns, and Proofpoint documented ChatGPT-themed malvertising delivering XWorm through ClickFix in 2024.

FAKE VERIFICATION SCREEN
↓
USER INSTRUCTED TO PASTE/RUN
↓
MALICIOUS CODE EXECUTION
↓
XWORM LOADER
↓
XWORM CLIENT
No malicious commands reproduced
This site does not reproduce malicious paste-and-run commands. The diagram is defensive and conceptual only.
XWorm Full Tech Access — 0.10 BTC — Access Granted, Network Mapped
@echophant