Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-25 · updated: 2026-09-25 · tags: [incident, global, phishing, macos] · confidence: high · severity: high · affected_sectors: [global] · au_impact: true

CTM360 published a report tracing ClickFix from a late-2023 novelty to a subscription product with on-chain infrastructure and a state-sponsored user base, built on a census of roughly 17,000 URLs. The research reports 47% of initial-access cases handled by Microsoft's Defender Experts team in 2025 attributed to ClickFix — ahead of conventional phishing — an ESET-measured 517% rise into the first half of 2025 and a further 108% between the second half of 2025 and the first half of 2026. MITRE assigned the behaviour its own sub-technique, T1204.004 (User Execution: Malicious Copy and Paste), in March 2025, covering Windows, macOS and Linux. The technique defeats familiar controls by design: no vulnerability for a scanner to find, no attachment to detonate, no file for reputation scoring, just a clipboard payload pasted by an authenticated user into a signed, present-on-every-system binary. CTM360's operational conclusion is the one that should change defensive posture — domain blocking is no longer a sufficient countermeasure.

Attribute Detail
Sector Global (Macro)
Date 2026-09-25
Source The Hacker News
Reliability Tier 2