ClickFix Detection & Automated Phishing Response: VMRay + KnowBe4 PhishER Integration
VMRay Webinar Highlight

ClickFix Detection & Automated Phishing Response:
VMRay + KnowBe4 PhishER

Phishing Triage SOC Automation Threat Intelligence · June 2026 · 10 min read
1,265% rise in phishing attacks since 2022
31% of SOC teams take 5+ hours to respond
<1hr critical window to capture phishing infrastructure

Phishing has changed. Where attacks once relied on a single malicious link leading directly to a credential harvesting page, today's campaigns are multi-stage, heavily obfuscated, and built to defeat both automated filters and manual analysis. Fake CAPTCHAs, QR codes embedded in PDFs, ClickFix clipboard injection, malicious SVGs — modern phishing is an attack chain, not a single event.

For security teams still relying on a shared security mailbox and manual triage, that shift has created a dangerous gap. Only 29% of organisations respond to phishing threats within the critical one-hour window. For 31% of teams, response times stretch to five hours or more — time an attacker can use to spread laterally, harvest credentials, or execute payloads across the environment.

This post covers how the integration between VMRay's malware sandbox and KnowBe4's PhishER platform closes that gap: automating phishing triage, detecting evasive threats like ClickFix, extracting IOCs from multi-stage attack chains, and enabling faster, more confident incident response.


What Is KnowBe4 PhishER and Why Does It Matter for SOC Teams?

KnowBe4 PhishER is an email incident response platform designed to replace the security mailbox with an automated triage and remediation workflow. When a user reports a suspicious email, PhishER ingests it, applies machine learning classification to tag it as clean, spam, or threat, and triggers pre-configured response actions based on those tags.

Those actions can include adding malicious domains directly to a Microsoft 365 block list, running PhishRip to automatically pull a reported email from every other affected inbox across the organisation, and launching PhishFlip campaigns that turn confirmed phishing emails into security awareness training exercises.

The result is a significant reduction in manual SOC workload. Instead of triaging hundreds of reported emails by hand, analysts work within an automated workflow that handles classification and initial remediation — and surfaces only the cases that genuinely need human review.

The boundary PhishER doesn't cross: PhishER handles the email layer well. What it doesn't do is go deeper into the artifacts inside that email — the attachments, embedded URLs, and multi-stage delivery chains that increasingly define modern phishing. That's precisely where VMRay steps in.

Why Multi-Stage Phishing Demands Sandbox Analysis

The most dangerous phishing emails today don't look dangerous. The malicious content isn't in the email itself — it's buried two, three, or four steps down a deliberate chain of decoys.

A recent example shared during the joint VMRay and KnowBe4 webinar illustrates the pattern well: an email arrives appearing to be an HR policy update, with a PDF attachment. The PDF contains a QR code for employees to acknowledge they've read the document. The QR code resolves to a URL. That URL leads to a fake CAPTCHA. After the CAPTCHA, a ClickFix page instructs the user to open PowerShell as administrator and paste clipboard contents. The clipboard holds a malicious batch script that reaches out to a C2 server.

HR EMAIL PDF attachment PDF + QR CODE Resolves URL FAKE CAPTCHA Gating page CLICKFIX PAGE Clipboard inject POWERSHELL Batch script C2 PAYLOAD Data exfil / malware ↑ VMRay recursively detonates every stage automatically
A typical ClickFix attack chain — six stages, zero detections at the email layer without sandbox analysis.

At each stage, the threat is invisible to reputation-based tools. VirusTotal had no detections on any of the artefacts. The initial PDF was clean — no exploited vulnerabilities, nothing an EDR agent would flag. The attack relied entirely on user interaction to progress, which is exactly why automated sandbox detonation is the right response.


How VMRay Detects ClickFix and Multi-Stage Phishing Threats

VMRay is a malware sandbox purpose-built for evasive threats. When integrated with PhishER, VMRay automatically pulls every reported email, extracts all attachments and URLs, and detonates each recursively — following the full attack chain the way a real user would.

Hypervisor-Level Monitoring

Operates below the OS — the analysis VM is unmodified and invisible to evasion checks on memory, timing, or tooling.

Behavioural AI Agent

Clicks links, solves CAPTCHAs, opens files, and follows redirects — progressing through multi-stage chains that stall passive tools.

Recursive Detonation

Every artefact found — QR codes, URLs, clipboard payloads — is detonated as a new analysis object automatically.

Structured IOC Extraction

C2 addresses, PowerShell download locations, file hashes — artefacts invisible to any reputation-based feed.

"When we look into the phishing landscape, we see more and more that old-fashioned phishing is not like it used to be — just a link and then credentials. The credit harvesting page is hidden behind one or several decoys. VMRay goes down the whole attack chain."

— Andrey, Product Manager, VMRay

The Value of the Golden Hour in Phishing Investigations

One aspect of the VMRay and PhishER integration that often goes unnoticed is its value for retrospective investigation, not just real-time triage.

Phishing infrastructure is ephemeral. Credential harvesting pages, ClickFix landing sites, and C2 servers are typically taken down within hours of a campaign being detected. If an analyst circles back after the fact, they will often find that the malicious URLs no longer resolve — leaving only the initial email as evidence.

Capturing evidence while infrastructure is live: Because VMRay detonates every reported email automatically as it arrives in PhishER, the full analysis — rendered pages, extracted payloads, network connections, and IOCs — is captured during the golden hour, while phishing infrastructure is still live. That data remains available even after the infrastructure disappears.

This gives incident responders the full attack chain for investigation, attribution, and downstream remediation — even when the phishing campaign was discovered days after the initial wave.


Setting Up the VMRay and KnowBe4 PhishER Integration

The integration is designed to be operational within five minutes. You'll need an active VMRay account (cloud or on-premises; a US data centre is available for organisations with data residency requirements) and a running PhishER instance.

  1. Add the KnowBe4 connector in VMRay Navigate to Analysis Settings in your VMRay console, select KnowBe4, and give the connector a name.
  2. Provide your PhishER URL and API token Generate an API token within PhishER and paste it into the VMRay connector configuration alongside your PhishER account URL.
  3. Set a polling interval VMRay pulls new emails from PhishER on a schedule — ten minutes by default, configurable to your needs.
  4. Configure action rules in PhishER Create rules that trigger on VMRay verdict tags (suspicious, malicious, low risk) to automate remediation steps.

VMRay writes the verdict, threat name, and a link to the full analysis report back into PhishER as tags, which the PhishER rule engine can act on immediately.


Automating Phishing Triage with VMRay Tags in PhishER

Once VMRay tags are flowing into PhishER, the four-step automation workflow takes minutes to configure. Create an action rule that triggers on a VMRay verdict tag. Configure what the action does — update status, set priority, route to an analyst queue. Optionally send a positive reinforcement message to the reporting user. Enable PhishRip to remove matched emails from all affected inboxes, and PhishFlip to convert the confirmed phishing email into a training campaign.

Nothing is enabled by default. Every step is optional and configurable to fit your team's existing workflow. PhishFlip, PhishRip, and automated user notifications are each individually opt-in.

Who Benefits Most from This Integration?

SOC Teams

Sandbox-verified verdicts replace reputation-only classification, slashing manual triage volume.

MSSPs

A consistent, auditable analysis pipeline producing structured IOCs across every client environment.

CTI Teams

C2 addresses and download locations from recursive detonation enrich threat intel feeds.


Phishing Response That Goes Beyond the Inbox

The combination of KnowBe4 PhishER and VMRay addresses the full lifecycle of a phishing incident: collection and initial classification via PhishER, deep sandbox analysis and IOC extraction via VMRay, and automated remediation back through PhishER's action engine.

For security teams trying to close the gap between a reported email and a confident, well-evidenced response, the integration compresses that window significantly — and ensures that the data needed for investigation, remediation, and downstream protection is captured before phishing infrastructure disappears.

See the Integration in Your Environment

Request a VMRay account or book a personalised demo to see automated phishing triage and ClickFix detection in action.

Request a Demo More Resources