The Fix for ClickFix: How Huntress Detects and Responds to a ClickFix Attack
ClickFix attacks leave no file to scan or block, which is why most endpoint tools miss it. See how Huntress Attack Disruption kills the chain in under a second.
Jonathan Semon is a cybersecurity expert with a knack for breaking down the most complex threats and turning them into actionable insights. His passion for technology started young, when his curiosity led him to dismantle (and sometimes reassemble) anything he could get his hands on—including computers. By age 8, he was leafing through an SQL book, laying the foundation for a career defined by a relentless drive to "hunt the hunters."
At Huntress, Jonathan brings hands-on expertise in threat analysis, malware dissection, and adversary tradecraft to the24/7 Security Operations Center (SOC). Tasked with identifying real-world threats and helping defenders cut through the static, his day-to-day is all about turning attacks into teachable moments for the team. Before joining Huntress, Jonathan led a Managed Detection and Response team at Sophos, where he focused on endpoint telemetry and threat actor behaviors.
Jonathan holds a Bachelor’s and Master’s in Cybersecurity and Information Assurance, along with a suite of certifications, including ISACA’s CISM and CompTIA’s CASP+. He’s also a Microsoft-certified Cybersecurity Architect.
When he’s not busy tearing apart malware, Jonathan is building something entirely different—from furniture to sustainable homesteads. He runs a small farm with chickens, goats, and even honeybees, and spends his evenings playing goalie on the ice.
Favorite Cybersecurity Tip: "If you didn’t ask for it, don’t trust it. Always take the long way instead of clicking that shady link."
ClickFix attacks leave no file to scan or block, which is why most endpoint tools miss it. See how Huntress Attack Disruption kills the chain in under a second.
Huntress researchers reveal how attackers are exploiting ChatGPT Custom GPTs to spread ClickFix lures and DLL-sideloaded malware. See the full breakdown.
A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.
Exodus crypto wallet analysis by Huntress uncovered tampered installers hiding a modular RAT focused on stealing credentials, not coins.
Huntress researcher uncovers post-Black Hat & DEF CON phishing campaign using X DMs & malicious documents to deliver AMOS, NetSupport RAT, and other malware.
An AMOS infostealer alert looked routine until Huntress ruled out every known delivery vector. What they found instead: malware being delivered through ChatGPT and Grok themselves.