
May 2025 continued the trend of high tempo across the cyber threat landscape. While ransomware remained a constant, and geopolitical tensions increasingly spilled into cyberspace, the month was defined by social engineering, specifically the widespread “ClickFix” malware wave.
The standout threat in May was a large-scale ClickFix campaign. This activity was mostly observed targeting public and private organisations in Portugal, particularly within the government, finance, and transportation sectors.
These attacks represent a shift away from complex software exploitation toward direct user manipulation:
The ClickFix wave demonstrated that attackers bypass traditional perimeter security by leveraging a user’s willingness to troubleshoot their own systems, effectively using “living off the land” legitimate administrative tools (like PowerShell) to execute obfuscated code.
Organizations should focus on:
May 2025 showed that modern malware waves don’t always arrive through complex exploits; sometimes, they arrive one convincing “Clickfix” at a time.
This entry is published as part of the SOCshare project (No. 101145843), which we are running together with Vilnius City Municipality. It is partly funded by the European Union. The views and opinions expressed are those of the authors alone and do not necessarily reflect those of the European Union or the European Cyber Security Centre of Excellence. Neither the European Union nor the European Cyber Security Centre of Excellence can be held responsible for them.