Threat Intelligence

ClickFix Attack Now Tops Enterprise Break-Ins, Tricking Users Into Infecting Themselves

The Hacker News · 24 Sept 2026
Key Takeaway Train staff to never paste or run commands they are asked to copy from a website, no matter how official the prompt looks, and treat unexpected 'fix it yourself' pop-ups as a red flag.

A new global threat report from CTM360 traces a technique called ClickFix from a minor novelty in late 2023 to what is now the most common way attackers gain initial access to enterprise networks. Unlike traditional attacks, ClickFix does not rely on an exploit, a malicious attachment, or a file being downloaded. Instead, a fake page tells the user something is wrong, such as a failed verification check or a document that will not open, then offers a fix. The instructions quietly copy a malicious command to the clipboard and ask the user to paste it into a trusted system tool and press Enter.

Because the command is entered manually by a real, logged-in user into a legitimate signed program already present on the device, there is nothing for antivirus, email filters, or vulnerability scanners to catch. This makes ClickFix extremely hard to detect using traditional defenses. The report notes that Microsoft attributed 47% of initial-access cases handled by its Defender Experts team in 2025 to ClickFix, and ESET recorded a 517% rise in the technique into the first half of 2025, with a further 108% increase since. MITRE has now given it a dedicated classification, confirming it affects Windows, macOS and Linux systems.

The report analysed over 17,000 infected URLs hosting fake verification pages, thousands of which were still active, alongside a detailed look at a single compromised WordPress site, tracing the full path from an initial infected page to information-stealing malware running on a victim's machine.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.