{"id":86791,"date":"2025-11-30T10:42:31","date_gmt":"2025-11-30T07:12:31","guid":{"rendered":"https:\/\/falnic.com\/blog\/?p=86791"},"modified":"2025-11-30T10:53:54","modified_gmt":"2025-11-30T07:23:54","slug":"new-wave-of-clickfix-attacks","status":"publish","type":"post","link":"https:\/\/falnic.com\/blog\/new-wave-of-clickfix-attacks.html","title":{"rendered":"\u0645\u0648\u062c \u062c\u062f\u06cc\u062f \u062d\u0645\u0644\u0627\u062a ClickFix \u0628\u0627 \u0635\u0641\u062d\u0647 \u062c\u0639\u0644\u06cc Windows Update\u061b \u0645\u062f\u06cc\u0631\u0627\u0646 \u0634\u0628\u06a9\u0647 \u0633\u0631\u06cc\u0639\u200c\u062a\u0631 Run \u0648\u06cc\u0646\u062f\u0648\u0632 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0639\u0627\u062f\u06cc \u0631\u0627 \u063a\u06cc\u0631\u0641\u0639\u0627\u0644 \u06a9\u0646\u0646\u062f!"},"content":{"rendered":"<figure class=\"wp-block-post-featured-image\"><img loading=\"lazy\" decoding=\"async\" width=\"694\" height=\"332\" src=\"https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/clickfix-attack-uses-fake-windows-update-screen.webp\" class=\"attachment-post-thumbnail size-post-thumbnail wp-post-image no-lazy\" alt=\"\u0645\u0648\u062c \u062c\u062f\u06cc\u062f \u062d\u0645\u0644\u0627\u062a ClickFix \u0628\u0627 \u0635\u0641\u062d\u0647 \u062c\u0639\u0644\u06cc Windows Update\" style=\"object-fit:cover;\" srcset=\"https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/clickfix-attack-uses-fake-windows-update-screen.webp 694w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/clickfix-attack-uses-fake-windows-update-screen-490x234.webp 490w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/clickfix-attack-uses-fake-windows-update-screen-150x72.webp 150w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/clickfix-attack-uses-fake-windows-update-screen-220x105.webp 220w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/clickfix-attack-uses-fake-windows-update-screen-390x187.webp 390w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><\/figure>\n\n\n<p>\u06cc\u06a9 \u0635\u0641\u062d\u0647 \u0639\u0627\u062f\u06cc \u0648 \u0645\u0648\u062c\u0647 (\u0627\u0645\u0627 \u06a9\u0627\u0645\u0644\u0627\u064b \u0641\u06cc\u06a9) \u0627\u0632 \u00abWindows Update\u00bb\u060c \u0628\u0647 \u0637\u0639\u0645\u0647\u200c\u0627\u06cc \u062c\u0630\u0627\u0628 \u0628\u0631\u0627\u06cc \u0641\u0631\u06cc\u0628 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0648 \u0622\u0644\u0648\u062f\u0647 \u06a9\u0631\u062f\u0646 \u0633\u06cc\u0633\u062a\u0645 \u0622\u0646\u0647\u0627 \u0628\u0647 \u0628\u062f\u0627\u0641\u0632\u0627\u0631 \u062a\u0628\u062f\u06cc\u0644 \u0634\u062f\u0647 \u0627\u0633\u062a! \u0627\u06cc\u0646 \u0635\u0641\u062d\u0647 \u062c\u0639\u0644\u06cc\u060c \u0628\u0627 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u0627\u062c\u0631\u0627\u06cc \u062f\u0633\u062a\u0648\u0631\u0627\u0644\u0639\u0645\u0644\u200c\u0647\u0627\u06cc \u0686\u0646\u062f\u0645\u0631\u062d\u0644\u0647\u200c\u0627\u06cc \u0648 \u0686\u0646\u062f \u062a\u06a9\u0646\u06cc\u06a9 \u0646\u0627\u0645\u062a\u0639\u0627\u0631\u0641 \u062a\u0631\u06a9\u06cc\u0628 \u0634\u062f\u0647 \u0648 \u0647\u0631 \u0686\u06cc\u0632\u06cc \u0631\u0627 \u06a9\u0647 \u0628\u0631\u0627\u06cc \u0639\u0628\u0648\u0631 \u0627\u0632 \u0644\u0627\u06cc\u0647\u200c\u0647\u0627\u06cc \u062f\u0641\u0627\u0639\u06cc \u0633\u06cc\u0633\u062a\u0645\u200c\u0647\u0627 \u0648 \u062f\u0632\u062f\u06cc\u062f\u0646 \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0646\u06cc\u0627\u0632 \u0627\u0633\u062a\u060c \u0641\u0631\u0627\u0647\u0645 \u06a9\u0631\u062f\u0647 \u0627\u0633\u062a! \u062f\u0631 \u0627\u062f\u0627\u0645\u0647 \u0628\u0627 \u0645\u0648\u062c \u062c\u062f\u06cc\u062f<strong> \u062d\u0645\u0644\u0627\u062a ClickFix <\/strong>\u06a9\u0647 \u0628\u0627 \u0646\u0645\u0627\u06cc\u0634 \u06cc\u06a9 \u0635\u0641\u062d\u0647 \u062c\u0639\u0644\u06cc \u0627\u0632 \u0648\u06cc\u0646\u062f\u0648\u0632 \u0622\u067e\u062f\u06cc\u062a \u0628\u0647\u200c\u0631\u0627\u0647 \u0627\u0641\u062a\u0627\u062f\u0647\u060c \u0628\u06cc\u0634\u062a\u0631 \u0622\u0634\u0646\u0627 \u0645\u06cc\u200c\u0634\u0648\u06cc\u0645.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u0631\u0634\u062f \u0633\u0631\u06cc\u0639 \u062d\u0645\u0644\u0627\u062a ClickFix \u0648 \u06a9\u0645\u067e\u06cc\u0646\u200c\u0647\u0627\u06cc \u0628\u062f\u0627\u0641\u0632\u0627\u0631\u06cc<\/h2>\n\n\n\n<p>\u0645\u062d\u0642\u0642\u0627\u0646 \u067e\u0644\u062a\u0641\u0631\u0645 \u0627\u0645\u0646\u06cc\u062a\u06cc Huntress \u0628\u0647 \u062a\u0627\u0632\u06af\u06cc \u0627\u0639\u0644\u0627\u0645 \u06a9\u0631\u062f\u0647\u200c\u0627\u0646\u062f: \u00ab\u0627\u0632 \u0627\u0628\u062a\u062f\u0627\u06cc \u0627\u06a9\u062a\u0628\u0631 2025 \u062a\u0627 \u06a9\u0646\u0648\u0646\u060c \u0686\u0646\u062f\u06cc\u0646 \u0633\u0627\u06cc\u062a \u0637\u0639\u0645\u0647 ClickFix \u0631\u0627 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u06a9\u0631\u062f\u0647\u200c\u0627\u06cc\u0645 \u06a9\u0647 \u0642\u0631\u0628\u0627\u0646\u06cc \u0631\u0627 \u0641\u0631\u06cc\u0628 \u0645\u06cc\u200c\u062f\u0647\u0646\u062f \u062a\u0627 \u06cc\u06a9 \u062f\u0633\u062a\u0648\u0631 \u0645\u062e\u0631\u0628 \u0631\u0627 \u0627\u062c\u0631\u0627 \u06a9\u0646\u062f. \u0647\u0645\u0647 \u0627\u06cc\u0646 \u0633\u0627\u06cc\u062a\u200c\u0647\u0627 \u0627\u0632 \u06cc\u06a9 \u0627\u0644\u06af\u0648\u06cc \u062b\u0627\u0628\u062a \u067e\u06cc\u0631\u0648\u06cc \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f \u0648 \u0637\u06cc \u06cc\u06a9 \u0632\u0646\u062c\u06cc\u0631\u0647 \u0627\u062c\u0631\u0627\u06cc\u06cc \u0645\u0646\u062d\u0635\u0631\u0628\u0647\u200c\u0641\u0631\u062f\u060c \u0622\u0633\u06cc\u0628 \u062e\u0648\u062f \u0631\u0627 \u0628\u0647 \u0642\u0631\u0628\u0627\u0646\u06cc \u0648\u0627\u0631\u062f \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f\u00bb.<\/p>\n\n\n\n<p>\u062f\u0631 \u0646\u0633\u062e\u0647\u200c\u0647\u0627\u06cc \u0627\u0648\u0644\u06cc\u0647\u060c \u0635\u0641\u062d\u0647 \u0637\u0639\u0645\u0647 \u06cc\u06a9 \u067e\u0646\u062c\u0631\u0647 \u0645\u0639\u0645\u0648\u0644\u06cc \u00ab\u062a\u0623\u06cc\u06cc\u062f \u0627\u0646\u0633\u0627\u0646\u06cc\u00bb (Human Verification) \u0631\u0627 \u0646\u0634\u0627\u0646 \u0645\u06cc\u200c\u062f\u0627\u062f \u0648 \u067e\u0633 \u0627\u0632 \u0622\u0646 \u0627\u0632 \u06a9\u0627\u0631\u0628\u0631 \u0645\u06cc\u200c\u062e\u0648\u0627\u0633\u062a \u062a\u0627 \u0645\u0631\u0627\u062d\u0644 \u0632\u06cc\u0631 \u0631\u0627 \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u062f:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u0627\u0628\u062a\u062f\u0627 \u06a9\u0644\u06cc\u062f\u0647\u0627\u06cc Win+R \u0631\u0627 \u0641\u0634\u0627\u0631 \u062f\u0647\u062f \u062a\u0627 \u067e\u0646\u062c\u0631\u0647 Run \u0628\u0627\u0632 \u0634\u0648\u062f.<\/li>\n\n\n\n<li>\u0633\u067e\u0633 \u06a9\u0644\u06cc\u062f\u0647\u0627\u06cc Ctrl+V \u0631\u0627 \u0628\u0632\u0646\u062f \u062a\u0627 \u062f\u0633\u062a\u0648\u0631\u06cc \u06a9\u0647 \u0628\u0647\u200c\u0637\u0648\u0631 \u062e\u0648\u062f\u06a9\u0627\u0631 \u062f\u0631 \u06a9\u0644\u06cc\u067e\u200c\u0628\u0648\u0631\u062f \u06a9\u067e\u06cc \u0634\u062f\u0647\u060c \u062f\u0631 \u067e\u0646\u062c\u0631\u0647 Run \u0642\u0631\u0627\u0631 \u06af\u06cc\u0631\u062f.<\/li>\n\n\n\n<li>\u0648 \u062f\u0631 \u0646\u0647\u0627\u06cc\u062a \u06a9\u0644\u06cc\u062f Enter \u0631\u0627 \u0628\u0632\u0646\u062f \u062a\u0627 \u062f\u0633\u062a\u0648\u0631 \u0627\u062c\u0631\u0627 \u0634\u0648\u062f.<\/li>\n<\/ul>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"694\" height=\"332\" src=\"https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/initial-clickfax-attacks.webp\" alt=\"\u0646\u0633\u062e\u0647 \u0627\u0648\u0644\u06cc\u0647 \u062d\u0645\u0644\u0627\u062a ClickFix \u0628\u0627 \u067e\u0646\u062c\u0631\u0647 Human Verification\" class=\"wp-image-86794\" title=\"\u062f\u0631 \u0646\u0633\u062e\u0647\u200c\u0647\u0627\u06cc \u0627\u0648\u0644\u06cc\u0647\u060c \u0635\u0641\u062d\u0647 \u0637\u0639\u0645\u0647 \u06cc\u06a9 \u067e\u0646\u062c\u0631\u0647 \u0645\u0639\u0645\u0648\u0644\u06cc \u00ab\u062a\u0623\u06cc\u06cc\u062f \u0627\u0646\u0633\u0627\u0646\u06cc\u00bb (Human Verification) \u0631\u0627 \u0646\u0634\u0627\u0646 \u0645\u06cc\u200c\u062f\u0627\u062f \u0648 \u067e\u0633 \u0627\u0632 \u0622\u0646 \u0627\u0632 \u06a9\u0627\u0631\u0628\u0631 \u0645\u06cc\u200c\u062e\u0648\u0627\u0633\u062a \u062a\u0627 \u06cc\u06a9 \u0633\u0631\u06cc \u0645\u0631\u0627\u062d\u0644 \u0631\u0627 \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u062f.\" srcset=\"https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/initial-clickfax-attacks.webp 694w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/initial-clickfax-attacks-490x234.webp 490w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/initial-clickfax-attacks-150x72.webp 150w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/initial-clickfax-attacks-220x105.webp 220w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/initial-clickfax-attacks-390x187.webp 390w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><\/figure>\n<\/div>\n\n\n<p>\u062f\u0631 \u0646\u0633\u062e\u0647 \u062c\u062f\u06cc\u062f\u062a\u0631 \u0627\u06cc\u0646 \u06a9\u0645\u067e\u06cc\u0646\u060c \u0637\u0639\u0645\u0647 \u062a\u063a\u06cc\u06cc\u0631 \u06a9\u0631\u062f\u0647 \u0627\u0633\u062a: \u0648\u0642\u062a\u06cc \u06a9\u0627\u0631\u0628\u0631 \u0648\u0627\u0631\u062f \u0635\u0641\u062d\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f\u060c \u0645\u0631\u0648\u0631\u06af\u0631 \u0628\u0647\u200c\u0637\u0648\u0631 \u062e\u0648\u062f\u06a9\u0627\u0631 \u0628\u0647 \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645\u200c\u0635\u0641\u062d\u0647 \u0645\u06cc\u200c\u0631\u0648\u062f \u0648 \u06cc\u06a9 \u0635\u0641\u062d\u0647 \u0628\u0633\u06cc\u0627\u0631 \u0634\u0628\u06cc\u0647 \u0628\u0647 Windows Update \u0631\u0627 \u0646\u0645\u0627\u06cc\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f \u06a9\u0647 \u0627\u0632 \u06a9\u0627\u0631\u0628\u0631 \u0645\u06cc\u200c\u062e\u0648\u0627\u0647\u062f \u062a\u0627 \u00ab\u0628\u0631\u0627\u06cc \u062a\u06a9\u0645\u06cc\u0644 \u0628\u0647\u200c\u0631\u0648\u0632\u0631\u0633\u0627\u0646\u06cc\u00bb\u060c \u062f\u0642\u06cc\u0642\u0627\u064b \u0647\u0645\u0627\u0646 \u0645\u0631\u0627\u062d\u0644 \u0628\u0627\u0644\u0627 \u0631\u0627 \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u062f.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"694\" height=\"332\" src=\"https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/new-wave-of-clickfix-attacks-with-fake-windows-update-screen.webp\" alt=\"\u0645\u0648\u062c \u062c\u062f\u06cc\u062f \u062d\u0645\u0644\u0627\u062a ClickFix \u0628\u0627 \u0635\u0641\u062d\u0647 Windows Update\" class=\"wp-image-86795\" title=\"\u062f\u0631 \u0646\u0633\u062e\u0647 \u062c\u062f\u06cc\u062f\u062a\u0631 \u062d\u0645\u0644\u0627\u062a ClickFix\u060c \u0648\u0642\u062a\u06cc \u06a9\u0627\u0631\u0628\u0631 \u0648\u0627\u0631\u062f \u0635\u0641\u062d\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f\u060c \u0645\u0631\u0648\u0631\u06af\u0631 \u0628\u0647\u200c\u0637\u0648\u0631 \u062e\u0648\u062f\u06a9\u0627\u0631 \u0628\u0647 \u062d\u0627\u0644\u062a \u062a\u0645\u0627\u0645\u200c\u0635\u0641\u062d\u0647 \u0645\u06cc\u200c\u0631\u0648\u062f \u0648 \u06cc\u06a9 \u0635\u0641\u062d\u0647 \u0628\u0633\u06cc\u0627\u0631 \u0634\u0628\u06cc\u0647 \u0628\u0647 Windows Update \u0631\u0627 \u0646\u0645\u0627\u06cc\u0634 \u0645\u06cc\u200c\u062f\u0647\u062f.\" srcset=\"https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/new-wave-of-clickfix-attacks-with-fake-windows-update-screen.webp 694w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/new-wave-of-clickfix-attacks-with-fake-windows-update-screen-490x234.webp 490w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/new-wave-of-clickfix-attacks-with-fake-windows-update-screen-150x72.webp 150w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/new-wave-of-clickfix-attacks-with-fake-windows-update-screen-220x105.webp 220w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/new-wave-of-clickfix-attacks-with-fake-windows-update-screen-390x187.webp 390w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><\/figure>\n<\/div>\n\n\n<p>\u0627\u06af\u0631 \u06a9\u0627\u0631\u0628\u0631 \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631\u0627\u062a \u0631\u0627 \u0627\u0646\u062c\u0627\u0645 \u062f\u0647\u062f\u060c \u0632\u0646\u062c\u06cc\u0631\u0647 \u0622\u0644\u0648\u062f\u06af\u06cc \u0641\u0639\u0627\u0644 \u0645\u06cc\u200c\u0634\u0648\u062f \u0648 \u0645\u0645\u06a9\u0646 \u0627\u0633\u062a \u062f\u0631 \u0646\u0647\u0627\u06cc\u062a \u0633\u06cc\u0633\u062a\u0645 \u0627\u0648 \u0628\u0647 \u06cc\u06a9 <a href=\"https:\/\/falnic.com\/blog\/what-is-malware.html\" target=\"_blank\" rel=\"noreferrer noopener\">\u0628\u062f\u0627\u0641\u0632\u0627\u0631<\/a> \u062e\u0637\u0631\u0646\u0627\u06a9 \u0628\u0647 \u0646\u0627\u0645 Lumma \u06cc\u0627 \u062c\u0627\u0633\u0648\u0633\u200c\u0627\u0641\u0632\u0627\u0631 (\u062f\u0632\u062f \u0627\u0637\u0644\u0627\u0639\u0627\u062a) Rhadamanthys \u0622\u0644\u0648\u062f\u0647 \u0634\u0648\u062f.<\/p>\n\n\n\n<p>\u0637\u0628\u0642 \u0645\u0642\u0627\u0644\u0647 \u0645\u0646\u062a\u0634\u0631 \u0634\u062f\u0647 \u062f\u0631 <a href=\"https:\/\/www.huntress.com\/blog\/clickfix-malware-buried-in-images\" target=\"_blank\" rel=\"noreferrer noopener\">\u0628\u0644\u0627\u06af Huntress<\/a> \u0628\u0627 \u0648\u062c\u0648\u062f \u062a\u0641\u0627\u0648\u062a \u062f\u0631 \u0638\u0627\u0647\u0631 \u0635\u0641\u062d\u0627\u062a\u060c \u0647\u0631 \u062f\u0648 \u06a9\u0645\u067e\u06cc\u0646 \u0628\u0627 \u0627\u062c\u0631\u0627\u06cc \u062f\u0633\u062a\u0648\u0631 mshta.exe \u0622\u063a\u0627\u0632 \u0645\u06cc\u200c\u0634\u0648\u0646\u062f \u06a9\u0647 \u062d\u0627\u0648\u06cc \u06cc\u06a9 URL \u0634\u0627\u0645\u0644 \u0622\u062f\u0631\u0633 IP \u0627\u0633\u062a\u061b \u0622\u062f\u0631\u0633\u06cc \u06a9\u0647 \u0628\u062e\u0634 \u062f\u0648\u0645 \u0622\u0646 \u0647\u0645\u06cc\u0634\u0647 \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u0647\u06af\u0632 (Hex) \u0631\u0645\u0632\u06af\u0630\u0627\u0631\u06cc \u0634\u062f\u0647 \u0627\u0633\u062a. \u0627\u06cc\u0646 \u062f\u0633\u062a\u0648\u0631 \u062f\u0631 \u0646\u0647\u0627\u06cc\u062a \u0628\u0647 \u0627\u062c\u0631\u0627\u06cc \u06cc\u06a9 \u0644\u0648\u062f\u0631 \u0645\u062e\u0641\u06cc .NET \u0645\u0646\u062c\u0631 \u0645\u06cc\u200c\u0634\u0648\u062f \u06a9\u0647 \u06cc\u06a9\u200c\u0633\u0631\u06cc \u062f\u0633\u062a\u0648\u0631 \u0628\u0627\u06cc\u0646\u0631\u06cc (Shell Code) \u0628\u0633\u062a\u0647\u200c\u0628\u0646\u062f\u06cc\u200c\u0634\u062f\u0647 \u0628\u0627 <a href=\"https:\/\/github.com\/TheWover\/donut\" target=\"_blank\" rel=\"noreferrer noopener\">Donut<\/a> \u0631\u0627 \u0627\u0632 \u062f\u0627\u062e\u0644 \u062f\u0627\u062f\u0647\u200c\u0647\u0627\u06cc \u067e\u06cc\u06a9\u0633\u0644\u06cc \u062a\u0635\u0627\u0648\u06cc\u0631 PNG \u0627\u0633\u062a\u062e\u0631\u0627\u062c \u0645\u06cc\u200c\u06a9\u0646\u062f.<\/p>\n\n\n\n<p>\u062a\u0645\u0627\u0645 \u0641\u0631\u0622\u06cc\u0646\u062f \u0628\u0647 \u062f\u0627\u0645 \u0627\u0646\u062f\u0627\u062e\u062a\u0646 \u0642\u0631\u0628\u0627\u0646\u06cc\u060c \u0634\u0627\u0645\u0644 \u0646\u0635\u0628 \u0648 \u0627\u062c\u0631\u0627\u06cc \u0628\u062f\u0627\u0641\u0632\u0627\u0631\u060c \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u06a9\u0627\u0645\u0644\u0627\u064b \u062f\u0631\u0648\u0646\u200c\u062d\u0627\u0641\u0638\u0647\u200c\u0627\u06cc (in-memory) \u0627\u0646\u062c\u0627\u0645 \u0645\u06cc\u200c\u0634\u0648\u062f \u0648 \u0647\u06cc\u0686 \u0641\u0627\u06cc\u0644\u06cc \u0631\u0648\u06cc \u062f\u06cc\u0633\u06a9 \u0630\u062e\u06cc\u0631\u0647 \u0646\u0645\u06cc\u200c\u0634\u0648\u062f.<\/p>\n\n\n\n<p>\u0628\u0631\u0627\u06cc \u0641\u0631\u0627\u0631 \u0627\u0632 \u0634\u0646\u0627\u0633\u0627\u06cc\u06cc \u062a\u0648\u0633\u0637 \u0622\u0646\u062a\u06cc\u200c\u0648\u06cc\u0631\u0648\u0633\u200c\u0647\u0627 \u0648 \u062f\u0648\u0631 \u0632\u062f\u0646 \u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc \u0627\u0645\u0646\u06cc\u062a\u06cc Endpoint\u060c \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u0627\u0632 \u0627\u0633\u06a9\u0631\u06cc\u067e\u062a\u200c\u0647\u0627 \u0648 \u06a9\u062f\u0647\u0627\u06cc \u0645\u0628\u0647\u0645\u200c\u0633\u0627\u0632\u06cc\u200c\u0634\u062f\u0647 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f \u06a9\u0647 \u0628\u0647\u200c\u0635\u0648\u0631\u062a \u067e\u0648\u06cc\u0627 \u0628\u0627\u0631\u06af\u0630\u0627\u0631\u06cc \u0645\u06cc\u200c\u0634\u0648\u0646\u062f. \u0647\u0645\u0686\u0646\u06cc\u0646 \u0645\u0647\u0627\u062c\u0645\u0627\u0646 \u062f\u0631 \u0627\u06cc\u0646 \u062d\u0645\u0644\u0647 \u0627\u0632 Payload \u0647\u0627\u06cc \u0645\u062e\u0641\u06cc \u0648 \u0627\u0628\u0632\u0627\u0631\u0647\u0627 \u0648 \u0641\u0631\u0622\u06cc\u0646\u062f\u0647\u0627\u06cc \u0642\u0627\u0646\u0648\u0646\u06cc \u0633\u06cc\u0633\u062a\u0645\u200c\u0639\u0627\u0645\u0644 \u0628\u0647\u0631\u0647 \u0645\u06cc\u200c\u0628\u0631\u0646\u062f.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u0631\u0648\u0634 \u067e\u06cc\u0634\u06af\u06cc\u0631\u06cc \u0627\u0632 \u0645\u0648\u062c \u062c\u062f\u06cc\u062f \u062d\u0645\u0644\u0627\u062a ClickFix \u0686\u06cc\u0633\u062a\u061f<\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"694\" height=\"332\" src=\"https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/new-clickfix-attacks-structure.webp\" alt=\"\u0633\u0627\u062e\u062a\u0627\u0631 \u062d\u0645\u0644\u0627\u062a \u062c\u062f\u06cc\u062f ClickFix\" class=\"wp-image-86796\" srcset=\"https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/new-clickfix-attacks-structure.webp 694w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/new-clickfix-attacks-structure-490x234.webp 490w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/new-clickfix-attacks-structure-150x72.webp 150w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/new-clickfix-attacks-structure-220x105.webp 220w, https:\/\/falnic.com\/blog\/wp-content\/uploads\/2025\/11\/new-clickfix-attacks-structure-390x187.webp 390w\" sizes=\"auto, (max-width: 694px) 100vw, 694px\" \/><\/figure>\n<\/div>\n\n\n<p>\u062f\u0631 \u062d\u0627\u0644 \u062d\u0627\u0636\u0631 ClickFix \u06cc\u06a9\u06cc \u0627\u0632 \u0631\u0627\u06cc\u062c\u200c\u062a\u0631\u06cc\u0646 \u0648 \u0645\u0624\u062b\u0631\u062a\u0631\u06cc\u0646 \u062a\u0631\u0641\u0646\u062f\u0647\u0627\u06cc\u06cc \u0627\u0633\u062a \u06a9\u0647 \u062a\u0648\u0633\u0637 \u062a\u0648\u0632\u06cc\u0639\u200c\u06a9\u0646\u0646\u062f\u06af\u0627\u0646 \u0628\u062f\u0627\u0641\u0632\u0627\u0631 \u0645\u0648\u0631\u062f \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0642\u0631\u0627\u0631 \u0645\u06cc\u200c\u06af\u06cc\u0631\u062f. \u062d\u062a\u06cc \u06a9\u06cc\u062a\u200c\u0647\u0627\u06cc \u0641\u06cc\u0634\u06cc\u0646\u06af \u0622\u0645\u0627\u062f\u0647 \u0628\u0627 \u062a\u0645 ClickFix \u0628\u0631\u0627\u06cc \u0641\u0631\u0648\u0634 \u0628\u0647 \u0645\u0647\u0627\u062c\u0645\u0627\u0646\u06cc \u06a9\u0647 \u062a\u062c\u0631\u0628\u0647 \u0648 \u0645\u0647\u0627\u0631\u062a \u0641\u0646\u06cc \u06a9\u0645\u062a\u0631\u06cc \u062f\u0627\u0631\u0646\u062f\u060c \u062f\u0631 \u062f\u0633\u062a\u0631\u0633 \u0642\u0631\u0627\u0631 \u06af\u0631\u0641\u062a\u0647 \u0627\u0633\u062a!<\/p>\n\n\n\n<p>\u062f\u0633\u062a\u0648\u0631\u0627\u0644\u0639\u0645\u0644\u200c\u0647\u0627\u06cc\u06cc \u06a9\u0647 \u062f\u0631 \u0627\u06cc\u0646 \u062d\u0645\u0644\u0627\u062a \u0627\u0632 \u06a9\u0627\u0631\u0628\u0631 \u062e\u0648\u0627\u0633\u062a\u0647 \u0645\u06cc\u200c\u0634\u0648\u062f\u060c \u0628\u0633\u062a\u0647 \u0628\u0647 \u0627\u06cc\u0646\u06a9\u0647 \u06a9\u0627\u0631\u0628\u0631 \u0627\u0632 \u06a9\u062f\u0627\u0645 \u0633\u06cc\u0633\u062a\u0645\u200c\u0639\u0627\u0645\u0644 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0645\u06cc\u200c\u06a9\u0646\u062f (\u0648\u06cc\u0646\u062f\u0648\u0632\u060c \u0645\u06a9 \u06cc\u0627 \u0644\u06cc\u0646\u0648\u06a9\u0633)\u060c \u0645\u062a\u0641\u0627\u0648\u062a \u0627\u0633\u062a. \u0647\u0645\u0686\u0646\u06cc\u0646 \u0638\u0627\u0647\u0631 \u0635\u0641\u062d\u0627\u062a \u0637\u0639\u0645\u0647 \u0645\u062f\u0627\u0645 \u062f\u0631\u062d\u0627\u0644 \u0628\u0647\u200c\u0631\u0648\u0632\u0631\u0633\u0627\u0646\u06cc \u0648 \u062a\u063a\u06cc\u06cc\u0631 \u0627\u0633\u062a.<\/p>\n\n\n\n<p>\u06a9\u0627\u0631\u0634\u0646\u0627\u0633\u0627\u0646 \u0627\u0645\u0646\u06cc\u062a\u06cc \u0628\u0647 \u0645\u062f\u06cc\u0631\u0627\u0646 \u0634\u0628\u06a9\u0647 \u0633\u0627\u0632\u0645\u0627\u0646\u200c\u0647\u0627 \u062a\u0648\u0635\u06cc\u0647 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f \u06a9\u0647 \u0628\u0631\u0627\u06cc \u067e\u06cc\u0634\u06af\u06cc\u0631\u06cc \u0627\u0632 \u062d\u0645\u0644\u0627\u062a ClickFix\u060c \u067e\u0646\u062c\u0631\u0647 Run \u0648\u06cc\u0646\u062f\u0648\u0632 \u0631\u0627 \u0628\u0631\u0627\u06cc \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0639\u0627\u062f\u06cc \u063a\u06cc\u0631\u0641\u0639\u0627\u0644 \u06a9\u0646\u0646\u062f. \u0628\u0631\u0627\u06cc \u0627\u06cc\u0646 \u0645\u0646\u0638\u0648\u0631 \u0628\u0647\u062a\u0631 \u0627\u0633\u062a \u062a\u0627 \u062a\u063a\u06cc\u06cc\u0631\u0627\u062a \u0631\u062c\u06cc\u0633\u062a\u0631\u06cc \u0644\u0627\u0632\u0645 \u0631\u0627 \u0627\u0639\u0645\u0627\u0644 \u06a9\u0646\u06cc\u062f \u06cc\u0627 \u0627\u0632 \u0637\u0631\u06cc\u0642 Group Policy (GPO)\u060c \u0627\u0645\u06a9\u0627\u0646 \u062a\u0639\u0627\u0645\u0644 \u0628\u0627 Windows Run Box \u0631\u0627 \u0645\u0633\u062f\u0648\u062f \u06a9\u0646\u06cc\u062f.<\/p>\n\n\n\n<p>\u0639\u0644\u0627\u0648\u0647 \u0628\u0631 \u0627\u06cc\u0646\u060c \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0627\u062f\u0627\u0631\u0627\u062a\u060c \u0634\u0631\u06a9\u062a\u200c\u0647\u0627 \u0648 \u0633\u0627\u0632\u0645\u0627\u0646\u200c\u0647\u0627 \u0646\u06cc\u0632 \u0628\u0627\u06cc\u062f \u0622\u0645\u0648\u0632\u0634 \u0628\u0628\u06cc\u0646\u0646\u062f \u062a\u0627 \u0637\u0639\u0645\u0647\u200c\u0647\u0627 \u0648 \u0631\u0648\u0634 ClickFix \u0631\u0627 \u062a\u0634\u062e\u06cc\u0635 \u062f\u0647\u0646\u062f \u0648 \u0628\u0627 \u0627\u0646\u0648\u0627\u0639 \u0627\u06cc\u0646 \u062d\u0645\u0644\u0647 \u0622\u0634\u0646\u0627 \u0634\u0648\u0646\u062f.<\/p>\n\n\n\n<p>\u0647\u0645\u0686\u0646\u06cc\u0646 \u06a9\u0627\u0631\u0634\u0646\u0627\u0633\u0627\u0646 \u062a\u0648\u0635\u06cc\u0647 \u0645\u06cc\u200c\u06a9\u0646\u0646\u062f: \u00ab\u0628\u0627 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 <a href=\"https:\/\/falnic.com\/blog\/endpoint-detection-and-response-edr.html\" target=\"_blank\" rel=\"noreferrer noopener\">\u0633\u06cc\u0633\u062a\u0645 EDR<\/a>\u060c \u0646\u0638\u0627\u0631\u062a \u06a9\u0646\u06cc\u062f \u06a9\u0647 \u0622\u06cc\u0627 explorer.exe \u062f\u0631 \u062d\u0627\u0644 \u0627\u062c\u0631\u0627\u06cc mshta.exe\u060c powershell.exe \u06cc\u0627 \u0633\u0627\u06cc\u0631 \u0627\u0628\u0632\u0627\u0631\u0647\u0627\u06cc \u0642\u0627\u0646\u0648\u0646\u06cc \u0633\u06cc\u0633\u062a\u0645\u200c\u0639\u0627\u0645\u0644 \u0628\u0627 \u062e\u0637 \u0641\u0631\u0645\u0627\u0646\u200c\u0647\u0627\u06cc \u0646\u0627\u0645\u062a\u0639\u0627\u0631\u0641 \u0647\u0633\u062a \u06cc\u0627 \u0646\u0647\u00bb.<\/p>\n\n\n\n<p>\u062f\u0631 macOS \u0646\u06cc\u0632 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0627\u063a\u0644\u0628 \u0628\u0627 \u0637\u0639\u0645\u0647\u200c\u0627\u06cc \u0645\u0648\u0627\u062c\u0647 \u0645\u06cc\u200c\u0634\u0648\u0646\u062f \u06a9\u0647 \u0627\u0632 \u0622\u0646\u0647\u0627 \u0645\u06cc\u200c\u062e\u0648\u0627\u0647\u062f Terminal \u0631\u0627 \u0628\u0627\u0632 \u06a9\u0646\u0646\u062f \u0648 \u062f\u0633\u062a\u0648\u0631\u06cc \u0631\u0627 \u062f\u0631 \u0622\u0646 \u0648\u0627\u0631\u062f \u06a9\u0646\u0646\u062f. \u0645\u062f\u06cc\u0631\u0627\u0646 \u0634\u0628\u06a9\u0647 \u0645\u06cc\u200c\u062a\u0648\u0627\u0646\u0646\u062f \u062f\u0633\u062a\u0631\u0633\u06cc \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u063a\u06cc\u0631\u0627\u062f\u0645\u06cc\u0646 \u0628\u0647 Terminal \u0631\u0627 \u0645\u062d\u062f\u0648\u062f \u0648 \u0627\u062c\u0631\u0627\u06cc \u0627\u0633\u06a9\u0631\u06cc\u067e\u062a\u200c\u0647\u0627\u06cc \u0628\u062f\u0648\u0646 \u0627\u0645\u0636\u0627 \u0631\u0627 \u0627\u0632 \u0637\u0631\u06cc\u0642 \u0633\u06cc\u0627\u0633\u062a\u200c\u0647\u0627\u06cc MDM \u0645\u0633\u062f\u0648\u062f \u06a9\u0646\u0646\u062f.<\/p>\n\n\n\n<p><\/p>\n\n\n<div class=\"kk-star-ratings kksr-auto kksr-align-left kksr-valign-bottom\"\n    data-payload='{&quot;align&quot;:&quot;left&quot;,&quot;id&quot;:&quot;86791&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;2&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;4&quot;,&quot;greet&quot;:&quot;post&quot;,&quot;legend&quot;:&quot;5\\\/5 - (2 \u0627\u0645\u062a\u06cc\u0627\u0632)&quot;,&quot;size&quot;:&quot;20&quot;,&quot;title&quot;:&quot;\u0645\u0648\u062c \u062c\u062f\u06cc\u062f \u062d\u0645\u0644\u0627\u062a ClickFix \u0628\u0627 \u0635\u0641\u062d\u0647 \u062c\u0639\u0644\u06cc Windows Update\u061b \u0645\u062f\u06cc\u0631\u0627\u0646 \u0634\u0628\u06a9\u0647 \u0633\u0631\u06cc\u0639\u200c\u062a\u0631 Run \u0648\u06cc\u0646\u062f\u0648\u0632 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0639\u0627\u062f\u06cc \u0631\u0627 \u063a\u06cc\u0631\u0641\u0639\u0627\u0644 \u06a9\u0646\u0646\u062f!&quot;,&quot;width&quot;:&quot;118&quot;,&quot;_legend&quot;:&quot;{score}\\\/{best} - ({count} \u0627\u0645\u062a\u06cc\u0627\u0632)&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}'>\n            \n<div class=\"kksr-stars\">\n    \n<div class=\"kksr-stars-inactive\">\n            <div class=\"kksr-star\" data-star=\"1\" style=\"padding-left: 4px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"2\" style=\"padding-left: 4px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"3\" style=\"padding-left: 4px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"4\" style=\"padding-left: 4px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"5\" style=\"padding-left: 4px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n    <\/div>\n    \n<div class=\"kksr-stars-active\" style=\"width: 118px;\">\n            <div class=\"kksr-star\" style=\"padding-left: 4px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-left: 4px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-left: 4px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-left: 4px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-left: 4px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 20px; height: 20px;\"><\/div>\n        <\/div>\n    <\/div>\n<\/div>\n                \n\n<div class=\"kksr-legend\" style=\"font-size: 16px;\">\n            5\/5 - (2 \u0627\u0645\u062a\u06cc\u0627\u0632)    <\/div>\n    <\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u06cc\u06a9 \u0635\u0641\u062d\u0647 \u0639\u0627\u062f\u06cc \u0648 \u0645\u0648\u062c\u0647 (\u0627\u0645\u0627 \u06a9\u0627\u0645\u0644\u0627\u064b \u0641\u06cc\u06a9) \u0627\u0632 \u00abWindows Update\u00bb\u060c \u0628\u0647 \u0637\u0639\u0645\u0647\u200c\u0627\u06cc \u062c\u0630\u0627\u0628 \u0628\u0631\u0627\u06cc \u0641\u0631\u06cc\u0628 \u06a9\u0627\u0631\u0628\u0631\u0627\u0646 \u0648 \u0622\u0644\u0648\u062f\u0647 \u06a9\u0631\u062f\u0646 \u0633\u06cc\u0633\u062a\u0645 \u0622\u0646\u0647\u0627 \u0628\u0647 \u0628\u062f\u0627\u0641\u0632\u0627\u0631 \u062a\u0628\u062f\u06cc\u0644 \u0634\u062f\u0647 \u0627\u0633\u062a! \u0627\u06cc\u0646 \u0635\u0641\u062d\u0647 \u062c\u0639\u0644\u06cc\u060c \u0628\u0627 \u062f\u0631\u062e\u0648\u0627\u0633\u062a \u0627\u062c\u0631\u0627\u06cc \u062f\u0633\u062a\u0648\u0631\u0627\u0644\u0639\u0645\u0644\u200c\u0647\u0627\u06cc \u0686\u0646\u062f\u0645\u0631\u062d\u0644\u0647\u200c\u0627\u06cc \u0648 \u0686\u0646\u062f \u062a\u06a9\u0646\u06cc\u06a9 \u0646\u0627\u0645\u062a\u0639\u0627\u0631\u0641 \u062a\u0631\u06a9\u06cc\u0628 \u0634\u062f\u0647 \u0648 \u0647\u0631 \u0686\u06cc\u0632\u06cc \u0631\u0627 \u06a9\u0647 \u0628\u0631\u0627\u06cc \u0639\u0628\u0648\u0631 \u0627\u0632 \u0644\u0627\u06cc\u0647\u200c\u0647\u0627\u06cc \u062f\u0641\u0627\u0639\u06cc \u0633\u06cc\u0633\u062a\u0645\u200c\u0647\u0627 \u0648 \u062f\u0632\u062f\u06cc\u062f\u0646 \u0627\u0637\u0644\u0627\u0639\u0627\u062a &hellip;<\/p>\n","protected":false},"author":72,"featured_media":86793,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-86791","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/falnic.com\/blog\/wp-json\/wp\/v2\/posts\/86791","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/falnic.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/falnic.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/falnic.com\/blog\/wp-json\/wp\/v2\/users\/72"}],"replies":[{"embeddable":true,"href":"https:\/\/falnic.com\/blog\/wp-json\/wp\/v2\/comments?post=86791"}],"version-history":[{"count":3,"href":"https:\/\/falnic.com\/blog\/wp-json\/wp\/v2\/posts\/86791\/revisions"}],"predecessor-version":[{"id":86799,"href":"https:\/\/falnic.com\/blog\/wp-json\/wp\/v2\/posts\/86791\/revisions\/86799"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/falnic.com\/blog\/wp-json\/wp\/v2\/media\/86793"}],"wp:attachment":[{"href":"https:\/\/falnic.com\/blog\/wp-json\/wp\/v2\/media?parent=86791"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/falnic.com\/blog\/wp-json\/wp\/v2\/categories?post=86791"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/falnic.com\/blog\/wp-json\/wp\/v2\/tags?post=86791"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}