Malware · 75 days ago
ClickFix works because the user becomes the execution step. That means a normal-looking paste into a trusted prompt can look legitimate to AV and EDR, even though it is the handoff that runs the malware.
ReliaQuest says this tactic dominated malware delivery from March 1 to May 31, 2026, and it spread from Windows into macOS. The macOS change matters because attackers moved from Terminal to Script Editor after Apple added paste-time warnings in Terminal, and the payloads included Deepload and AMOS.
For defenders, the shift is not just a new lure. It shows the technique can move across platforms and around vendor warnings as long as users can paste commands into a trusted workflow.
2 sources covering this story
And the Winner in Dominant Malware Delivery? ClickFix
Researchers say the highly effective social engineering technique is no longer the exception for malware attacks — it's now the rule.
ClickFix Now Cybercriminals' Favorite Malware Delivery Technique
ReliaQuest report warns of a surge in ClickFix social engineering attacks against Windows and macOS users
Part of the PlainSec briefing for 2026-07-02