Malware · 8h ago
CTM360 says ClickFix now accounts for 47% of Microsoft Defender Experts’ 2025 initial-access cases, with more than 17,000 lure URLs in the wild and about 3,000 still serving at report time. The technique has moved from a novelty to a repeatable access path across Windows, macOS, and Linux.
The page does not drop a file or exploit a bug. It copies an attacker command to the clipboard, then persuades the user to paste it into a trusted native interface and press Enter, so the payload runs as an authenticated local action while domain blocking and file scanning see nothing to stop.
That shifts the exposure from the browser to the user’s shell and any infrastructure hosting the lure pages, including compromised WordPress sites. If your control story ends at the URL or the download, ClickFix leaves the decisive execution step outside that boundary.
1 source covering this story
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
ClickFix accounted for 47% of Microsoft Defender Experts initial-access cases in 2025, while a Polygon contract rotated lure hosts.
Part of the PlainSec briefing for 2026-09-24