New Clickfix variant ‘CrashFix’ deploying Python Remote Access Trojan | Microsoft Security Blog

New Clickfix variant ‘CrashFix’ deploying Python Remote Access Trojan | Microsoft Security Blog

By Microsoft Defender Security Research Team
Publication Date: 2026-02-05 18:51:00

In January 2026, Microsoft Defender Experts identified a new evolution in the ongoing ClickFix campaign. This updated tactic deliberately crashes victims’ browsers and then attempts to lure users into executing malicious commands under the pretext of restoring normal functionality.

This variant represents a notable escalation in ClickFix tradecraft, combining user disruption with social engineering to increase execution success while reducing reliance on traditional exploit techniques. The newly observed behavior has been designated CrashFix, reflecting a broader rise in browser‑based social engineering combined with living‑off‑the‑land binaries and Python‑based payload delivery. Threat actors are increasingly abusing trusted user actions and native OS utilities to bypass traditional defences, making behaviour‑based detection and user awareness critical.

Crashfix Attack life cycle.

This attack typically begins when a victim searches for an ad blocker and…