Malware · 8h ago

ClickFix Moves Malware Into Trusted Shells

CTM360 says ClickFix now accounts for 47% of Microsoft Defender Experts’ 2025 initial-access cases, with more than 17,000 lure URLs in the wild and about 3,000 still serving at report time. The technique has moved from a novelty to a repeatable access path across Windows, macOS, and Linux.

The page does not drop a file or exploit a bug. It copies an attacker command to the clipboard, then persuades the user to paste it into a trusted native interface and press Enter, so the payload runs as an authenticated local action while domain blocking and file scanning see nothing to stop.

That shifts the exposure from the browser to the user’s shell and any infrastructure hosting the lure pages, including compromised WordPress sites. If your control story ends at the URL or the download, ClickFix leaves the decisive execution step outside that boundary.

Timeline

Sources

1 source covering this story

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-24

Editions

Related stories