The Lure Isn't The Malware. It's Your Logo.
Recorded Future's Insikt GroupⓇ, our team of threat intelligence analysts and security researchers, has been tracking a technique called ClickFix as it works its way into a growing number of brand impersonation campaigns. We recently hosted a webinar digging into that research, and what stood out wasn't just the technique itself. There's no malware automatically installed, no exploit, just a page convincing enough that the victim ends up doing the damage themselves. It is also a strong example of the detection capabilities built into Malicious Site Monitoring, a new use case included in Digital Risk Protection, and a good way to show what those capabilities are actually built to catch.
How ClickFix actually works
ClickFix works by mimicking the visual language people already trust, a CAPTCHA prompt, a familiar logo, a "verify you're human" screen, and using that trust to get someone to run a command on their own machine. There's no code being smuggled past a firewall. The victim is the delivery mechanism.
That's also what makes it hard to catch with traditional tools. A page built to look exactly like a real verification screen doesn't behave like malware, and it doesn't trip the same alarms as a page trying to exploit a browser. It succeeds because the person on the other end believes they're completing something routine.
It's not static, either. The instructions can change depending on the operating system a victim is running, one path for Windows, a different one for macOS, which means the "fix" itself adapts to the target. A single signature or a one-off takedown was never going to keep up with that. Catching this at scale means watching for the pattern, not waiting to recognize a specific file.
Malicious Site Monitoring
This kind of research and the product built to act on it aren't two separate things. Digital Risk Protection's Malicious Site Monitoring is built to catch this exact category of infrastructure, phishing domains, lookalike sites, brand impersonation, fast enough to matter. Disposable infrastructure like this is designed to do its damage and disappear before anyone gets around to reporting it, so speed isn't just a nice-to-have here, it's a necessity.
Underneath that speed is a detection process built in layers. Analyst-built signatures catch known patterns with precision. Content similarity analysis can catch campaigns that move in clusters. Attackers often reuse the same page template across dozens of disposable domains, so even though each domain name looks unrelated, the pages themselves share the same structure underneath. A separate component flags a familiar logo or brand mark through screenshot analysis and Optical Character Recognition (OCR). Machine learning is often able to catch what the other methods might miss, sites that don't resemble any known signature or template, by predicting risk from the page's characteristics rather than requiring a direct match. That layered approach is what makes it possible to evaluate a massive volume of candidate domains and URLs every single day without generating excessive false positives.
From detection to takedown
Finding a threat fast doesn't help much if the next steps are still manual. The real shift in how Digital Risk Protection operates is this: detection, triage, and action now live in the same workflow.
Not every detection needs a human to look at it immediately, and that distinction matters. A multi-stage detection funnel helps filter raw monitoring volume down to those that could need a response, and for malicious sites specifically, an AI Triage Agent reviews flagged detections and delivers a verdict before anything reaches an analyst's queue. Instead of triaging a wall of alerts, teams are looking at a shortlist of things that already have context attached, what was found, why it matters, and what to do about it.
And when something does need action, takedown doesn't require a separate process. Coordination happens directly from the alert, one click, instead of manually chasing down registrars and hosting providers one by one.
What this means going forward
ClickFix is one campaign type. It won't be the last one built this way, and it almost certainly won't be the most sophisticated one we see this year. The interesting story isn't any single technique, it's that the same detection engine tracking it in a research report is the one running in production, watching for the next one before it has a name.
If you want to see that detection-to-action workflow in practice, not just malicious sites, but the full picture across dark web monitoring, code repository exposure, impersonation, and identity monitoring, take a self-guided click-through of Digital Risk Protection or request a demo. If you're already a customer, your account team can walk you through what this looks like against your own brand.
Frequently asked questions
Is ClickFix something Digital Risk Protection can actually detect, or just something Insikt Group writes about?
Both. The detection methodology behind the ClickFix research, layered signature, similarity, and machine learning analysis, is the same engine running inside Malicious Site Monitoring today. The research isn't separate from the product; it's built on it.
Is the AI Triage Agent available for this use case?
Yes. Malicious Site Monitoring is one of two use cases, alongside Dark Web Brand Monitoring, where the AI Triage Agent is live today. It reviews flagged detections and delivers a verdict before anything reaches an analyst's queue.
How do I get access to Digital Risk Protection?
It's available as a standalone solution or as part of Recorded Future's Core, Professional, and Elite platform packages. If you already use Recorded Future for brand monitoring, it's available to activate directly in the platform. If you're new to Recorded Future, request a demo to see it in action.