ClickFix Campaigns Abuse Legitimate Services for Persistent Access

Published September 8, 2026

Attackers are sending fake tech-support messages that trick users into installing a remote-control app. Once installed, the attackers can take over the user's computer without permission.

Report priority
Medium

How it works

  • Attackers send fake messages pretending to be from a user's company or IT support.
  • The message claims there's a problem with the user's computer or account and urges them to click a link or download an app.
  • The link or app is actually a remote-control tool like AnyDesk, TeamViewer, or Chrome Remote Desktop.
  • Once the user installs it, the attacker can connect to their computer and take control without their password.
  • The fake messages often look official, using company logos, employee names, or urgent warnings to pressure the user into acting fast.

What to do

If you received a fake tech-support message from your company or IT department and installed a remote-control app from it, check your email for suspicious messages with urgent warnings or links to download apps. If you installed AnyDesk, TeamViewer, or Chrome Remote Desktop after clicking a link in such a message, look for unexpected remote connections in your app logs or unusual activity on your device.

If you installed the app, immediately disconnect from the internet and uninstall it. Then, scan your computer with antivirus software and change all your passwords. Contact your company's IT support to report the incident and ask if they can check for unauthorized access. If you didn't install anything, delete the suspicious email and avoid clicking similar links in the future.

Technical details

An attacker sends an email to an employee at a company, pretending to be from the IT department. The email says the user's account has been locked due to suspicious activity and provides a link to download a 'security tool' to unlock it. The link actually installs a remote-control app, giving the attacker full access to the user's computer.

Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.