# ClickFix Removes Your Background but Leaves the Malware

DevFeed: [ClickFix Removes Your Background but Leaves the Malware](<https://devfeed.tech/articles/clickfix-removes-your-background-but-leaves-the-malware-54242.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/clickfix-castleloader-backgroundfix>)

Author: Anna Pham

Published: 2026-04-30T13:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [clickfix](<https://devfeed.tech/tags/clickfix.md>), [indicators-of-compromise](<https://devfeed.tech/tags/indicators-of-compromise.md>), [malware](<https://devfeed.tech/tags/malware.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [windows](<https://devfeed.tech/tags/windows.md>)

## AI overview

Huntress analyzes BackgroundFix, a ClickFix social engineering campaign that uses a fake image background-removal site to copy a malicious command to a visitor's clipboard. The command retrieves and executes a payload through Windows finger.exe, leading to CastleLoader and NetSupportRAT.

## Source excerpt

Your background is gone, but malware is here. Huntress breaks down BackgroundFix, a new ClickFix social engineering tactic involving CastleLoader, NetSupport RAT, and CastleStealer. Read the analysis.