ClickFix has emerged as a leading method for cyber attackers to infiltrate enterprise networks, bypassing traditional security measures. Our latest global threat report from CTM360 details the evolution of this technique from a niche tactic in late 2023 to a sophisticated subscription model backed by state actors, highlighting the diminishing effectiveness of blocking malicious domains.
Understanding the ClickFix Technique
The ClickFix attack strategy begins with a seemingly innocuous webpage presenting a problem for the user to solve. This could be a failed human verification check or a browser error. The site provides a solution, instructing users to copy a ‘fix’ to their clipboard and execute it in a trusted system interface. This process mimics legitimate administrative tasks, thus avoiding detection by security scanners.
This technique has become the primary entry point for intrusions in enterprise telemetry. In 2025, Microsoft’s Defender Experts attributed 47% of initial-access incidents to ClickFix, surpassing traditional phishing attacks. Additionally, ESET reported a 517% increase in these attacks in the first half of 2025, with another 108% rise by mid-2026. Recognizing its impact, MITRE categorized it under User Execution: Malicious Copy and Paste (T1204.004) in March 2025, affecting Windows, macOS, and Linux platforms.
Infrastructure and Targeting Tactics
ClickFix’s infrastructure is designed for resilience against takedowns. The attack leverages EtherHiding, a method using the Polygon blockchain to dynamically update lure hostnames without involving attacker domains. This approach allows the attack to persist even as individual domains are blocked or removed.
Targeting is highly customized and server-side, adapting to the visitor’s operating system. Analysis revealed that while Windows attacks were active, macOS and Linux pathways were prepared and ready for deployment. The system can suppress malicious overlays for repeat visitors, complicating efforts to analyze and counteract the threat.
Challenges in Detection and Response
One of the significant challenges in mitigating ClickFix is its ability to evade detection. The payload is tailored to the machine’s identity, using hardware and account fingerprints to ensure the correct target is compromised while misleading sandbox environments. This complicates traditional security tools’ ability to reliably detect and block the threat.
WordPress plays a crucial role in the delivery mechanism, providing the necessary infrastructure for legitimate-looking domains with real traffic. Attackers embed scripts into responses across various formats, making it difficult to identify and clean the infection without comprehensive measures.
Effective defenses include restricting clipboard-write permissions in managed browsers and forcing script interpreters through authenticated proxies, disrupting the attack chain at critical points.
To read the full analysis and explore detailed remediation strategies, access the complete CTM360 report.
