ClickFix Fake Decryption Error Spawns Piped Shell/PowerShell Command
Detects ClickFix-style social engineering attacks where users are prompted to copy and execute malicious commands in a shell environment. The rule triggers on process execution of terminal or shell binaries (zsh, sh, cmd.exe, powershell.exe) containing indicators of obfuscated execution or remote code downloading, such as piped shell commands (curl | sh/zsh) or PowerShell encoded command execution.
YARA-L

