Security researchers report that ClickFix has become a major initial-access technique, relying on social engineering rather than software exploits to trick users into pasting attacker-provided commands into Windows Run or macOS Terminal. ESET said detections rose 108% from H2 2025 to H1 2026, while RH-ISAC described a broader 517% increase from late 2024 into the first half of 2025 and noted that Microsoft saw the method in 47% of initial-access cases handled by Defender Experts. Attackers have expanded ClickFix beyond Windows to macOS, delivered it through compromised WordPress sites, and improved lures with fake BSOD screens, frozen document viewers, and service-specific error messages.
The technique is now used by both cybercriminals and state-backed groups, with RH-ISAC linking adoption to Sandworm, APT28, MuddyWater, and Kimsuky and citing Sandworm activity against organizations in Ukraine, including at least one compromise involving FreakyPoll malware. Researchers also observed ClickFix delivering malware such as ACR Stealer, OkoBot, TELEPUZ, ClickLock Stealer, and DriveSurge, while newer variants including CrashFix, FileFix, PromptFix, and ConsentFix show continued evolution. ESET additionally identified an "AI-fix" variant that abuses legitimate domains tied to Anthropic Artifact, OpenAI Canvas, and Microsoft Copilot Pages to display fake troubleshooting content for nonexistent AI problems, underscoring how attackers are blending trusted platforms, AI branding, and increasingly industrialized delivery infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
RH-ISAC reported that ClickFix infrastructure evolved toward API-driven delivery, orchestrator commands, and AMSI-evasion techniques, while underground kits lowered the barrier to entry. The report also highlighted newer variants including CrashFix, FileFix, PromptFix, and ConsentFix.
RH-ISAC reported that nation-state actors adopted ClickFix, including Sandworm, which used the technique against sensitive organizations in Ukraine. At least one resulting compromise involved FreakyPoll malware.
Researchers observed a 517% increase in ClickFix activity from late 2024 into the first half of 2025, reflecting its rapid growth as a social-engineering-based malware delivery technique. Microsoft also reported seeing ClickFix in 47% of initial-access cases handled by Defender Experts during this period.
A Medium article published on July 16, 2026 by researcher Ddosier proposed detecting ClickFix through a shared behavioral sequence: browser focus loss, shell interpreter execution, and outbound network activity within 60 seconds. The article mapped this invariant across Windows, macOS, and Linux and included example detections in KQL, Splunk SPL, and YARA-L.
ESET tracked an "AI-fix" ClickFix variant that used legitimate domains including Anthropic Artifact pages, OpenAI Canvas, and Microsoft Copilot Pages. The pages displayed fake troubleshooting content for nonexistent generative AI issues to trick users into executing attacker-supplied actions.
ESET reported that ClickFix expanded beyond Windows to target macOS. The campaign also used compromised WordPress sites and deceptive screens such as fake BSODs, frozen document viewers, and service-specific error messages.
ESET's H1 2026 threat reporting said ClickFix detections increased 108% compared with H2 2025. The growth was tied to attackers expanding into new environments and refining their social-engineering lures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcerhisac.org
Open sourceblog.knowbe4.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.