ClickFix works because the user becomes the execution step. That means a normal-looking paste into a trusted prompt can look legitimate to AV and EDR, even though it is the handoff that runs the malware.
ReliaQuest says this tactic dominated malware delivery from March 1 to May 31, 2026, and it spread from Windows into macOS. The macOS change matters because attackers moved from Terminal to Script Editor after Apple added paste-time warnings in Terminal, and the payloads included Deepload and AMOS.
For defenders, the shift is not just a new lure. It shows the technique can move across platforms and around vendor warnings as long as users can paste commands into a trusted workflow.