Remote workers are being hit by a new malware campaign that imitates the Google Meet interface with near-perfect accuracy. Attackers use a fake domain and a social engineering method called ClickFix to trick users into running a malicious PowerShell script. The script installs a Remote Access Trojan that gives attackers control over the victim’s system. Incident responders tied infections directly to the deceptive site through forensic artifacts stored in the system’s Master File Table.
Relevant Source (Sucuri): Fake Google Meet Page Tricks Users into Running PowerShell Malware
Sucuri analyzes a malicious Google Meet lookalike page that abuses ClickFix-style prompts to make users run a PowerShell command that downloads and executes a RAT, matching the attack chain described here.
Quick Facts
- Attackers use a fake Google Meet page hosted on gogl-meet[.]com
- Victims are shown a fake “Can’t join the meeting” error
- ClickFix prompts users to run Windows key + R and paste a malicious script
- The payload installs a Remote Access Trojan
- PowerShell scripts are padded with check mark symbols to mislead victims
- Forensics show the attack chain is tied directly to the fake site
How The ClickFix Attack Works
This campaign centers on a fraudulent Google Meet page designed to mimic the real interface with high accuracy. Instead of requesting login credentials, the page triggers a fake error that claims a camera or microphone failure and offers a guided “fix.” The attacker uses JavaScript to copy a malicious PowerShell script into the victim’s clipboard once they click the button. The user is then told to run Windows key plus R and paste the contents, which delivers the RAT. This method neatly sidesteps browser protections that would normally block suspicious downloads.
- Uses a ClickFix prompt instead of credential theft
- Copies malicious PowerShell code directly to the clipboard
- Relies on manual keystrokes to deploy the payload
The setup makes the victim believe they are fixing a technical issue while their device is being compromised in the background.
Relevant Source (Microsoft Security): Analyzing the ClickFix social engineering technique
Breaks down the ClickFix attack chain, showing how fake troubleshooting pages guide users to execute malicious clipboard-based commands via Windows tools like Run.
Why ClickFix Targeting Remote Work Matters
Remote workers tend to trust video meeting interfaces and react quickly when a platform reports a device problem. Attackers exploit that instinct to push victims toward physical interaction that typical security controls cannot block. The fake Meet page hides malicious behavior behind familiar visuals and misleading Unicode symbols. These symbols push the malicious code outside the visible part of the Run box and offer false reassurance.
- Visual mimicry boosts trust
- Browser security filters are bypassed
- Manual execution hides the malware path
- Branding shifts toward corporate tools
- RAT infections allow deep system control
This approach helps attackers target organizations that rely heavily on conferencing tools and creates a wider path for data theft and persistence.
Relevant Source (Palo Alto Networks Unit 42): Fix the Click: Preventing the ClickFix Attack Vector
Explains how ClickFix campaigns exploit employee trust and remote-work habits to deploy RATs and steal data, and outlines why these socially engineered attacks are so effective in modern workplaces.
ClickFix Defense Steps
Teams should strengthen detection, user awareness, and PowerShell monitoring to catch this type of attack early. Administrators can track unusual execution patterns from the Windows Run dialog, especially those containing large comment blocks or Unicode symbols. Security training should prepare users to avoid running unsolicited keystroke sequences or instructions from web popups.
Recommended actions include:
- Block suspicious domains such as gogl-meet[.]com
- Add rules to flag Run-originating PowerShell commands
- Train staff to ignore “fix instructions” from websites
- Require users to report abnormal conferencing errors
- Harden PowerShell logging and restrict its execution policies
A consistent response plan helps limit the risk from campaigns that blend social engineering with manual execution.
Relevant Source (CISA): Keeping PowerShell: Measures to Use and Embrace
Provides guidance on securing PowerShell through logging, configuration, and monitoring so defenders can detect and contain malicious scripts without disabling the tool entirely.
How ClickFix Fits Into The Larger Threat Landscape
Threat actors are refining ClickFix into a tool that blends familiar branding with subtle psychological pushes. A fake interface paired with a believable technical error creates a situation where victims act before thinking. The method pairs trust with urgency, two factors that increase the success rate of social engineering.
The shift toward impersonating business tools suggests attackers are focusing on organizations where video calls drive daily operations. This form of targeted deception will likely continue because it bypasses security controls and relies on user interaction that software cannot easily block.
Relevant Source (Group-IB): ClickFix: The Social Engineering Technique Hackers Use to Manipulate Victims
Describes how ClickFix blends fake prompts, urgency, and familiar branding to coerce users into executing malicious commands, aligning with the psychological setup outlined here.
Final ClickFix Security Lessons
Stopping ClickFix campaigns starts with recognizing that attackers now use trusted interfaces rather than generic phishing pages. Users should be cautious any time a conferencing tool asks for manual system commands. Security teams must monitor PowerShell activity and block suspicious domains to cut off the attack chain before the payload lands.
FAQ
What is ClickFix?
A social engineering technique that convinces users to run malicious commands through guided steps.
How does the fake Google Meet page work?
It shows a false error, copies malware into the clipboard, and prompts the user to paste it into the Run dialog.
Why doesn’t the browser block this attack?
The attack relies on manual execution, which bypasses browser-based protections.
What does the malware do after execution?
It installs a Remote Access Trojan that can give attackers full system access.
How can organizations detect this behavior?
Monitor PowerShell commands launched from the Run dialog, especially those containing heavy comment padding or unusual Unicode symbols.
How JENI Helps Strengthen Security
JENI supports safer computing by giving users a cleaner and more stable system that reduces the chances of hidden processes going unnoticed. A well-maintained device makes it easier to spot abnormal behavior tied to attacks like ClickFix where manual execution hides malicious activity. JENI’s performance tools help keep endpoints responsive so suspicious delays or sudden resource spikes stand out instead of blending in with routine clutter.
Key Advantages:
- Improves system stability so unusual processes are easier to detect
- Reduces background load and makes malicious activity more visible
- Supports healthier endpoints that are less prone to overlooked warning signs
Regular tune-ups create an environment where threats are harder to disguise. A streamlined system helps users recognize when something feels out of place, especially when fake interfaces attempt to shift attention away from what is happening underneath. Security always benefits from clear baselines because inconsistencies become more obvious. JENI works alongside existing security tools by keeping the system clean enough for real warnings to stand out.

