Known malicious kitcriticalphishing

Windows FileFix: paste-into-File-Explorer instructions (Win+E, Ctrl+L) — page content

family: filefix-explorer-2026-10

Fake verification pages that copy a command to the clipboard and tell the visitor to open File Explorer (Win+E), select its address bar (Ctrl+L), paste with Ctrl+V and press Enter. Text pasted into the File Explorer address bar is run as a command, so this is ClickFix without the Run dialog (known as FileFix). First seen here on 2026-10-04 on a Russian-language fake reCAPTCHA ('document access confirmation') whose command downloads a PowerShell script, mounts a disk image named like a tax document and runs an executable behind a decoy PDF. The same File Explorer steps also appear as an option in a multi-language ClickFix kit injected into compromised websites. No legitimate verification step asks visitors to run a command.

Anchors

YARA ruleClickFix_FileFix_Explorer_Lure

Provenance

Added: 2026-10-04 12:33
Page rule: needs the File Explorer step, the address-bar step, a clipboard write and a copied command that starts with a Windows command interpreter, plus a robot or verification pretext or a command padded to look like a file path. A how-to page about File Explorer shortcuts does not match on its own.

Sightings (8)

HostScanScriptMatchWhen
mepi.com.sa#html3fa3c3e8…https://mepi.com.sa#htmlyara2026-10-04 12:35
cisco.parivpn.ru92b80206…https://cisco.parivpn.ru/#htmlyara2026-10-04 12:35
mx1.prod.rossko.sud6ff2dea…https://mx1.prod.rossko.su/#htmlyara2026-10-04 12:35
dms.cabinet-ingos.rudaaa841e…https://dms.cabinet-ingos.ru/#htmlyara2026-10-04 12:35
buh.reallstbank.ru21bd62a6…https://buh.reallstbank.ru/#htmlyara2026-10-04 12:35
ai.parivpn.ru66a58636…https://ai.parivpn.ru/#htmlyara2026-10-04 12:35
vpn.reallstbank.ru2a288882…https://vpn.reallstbank.ru/#htmlyara2026-10-04 12:35
alfastrahv.ru9849fa57…https://alfastrahv.ru/#htmlyara2026-10-04 12:35