ClickFix is a social engineering technique that needs no exploit, attachment, or file on disk: a compromised page presents a fake problem, copies a "fix" to the clipboard, and convinces the user to paste it into a trusted system tool. According to a new CTM360 report, it has become the leading initial-access technique in enterprise intrusion telemetry. Microsoft attributed 47% of the initial-access cases handled by its Defender Experts team in 2025 to ClickFix, while ESET measured a 517% rise into the first half of 2025 and a further 108% increase into the first half of 2026. MITRE assigned the behavior its own sub-technique, T1204.004, covering Windows, macOS, and Linux.
The infrastructure is built to survive takedowns. The injected script on a compromised website contains no attacker domain; instead, the visitor's browser makes a read-only call to a smart contract on the Polygon blockchain to retrieve the current lure hostname. During one day of analysis, that contract returned three different lure hosts in sequence without any modification to the infected sites. Telegram channel descriptions and a Steam profile page similarly resolve the malware's command-and-control address, so no single takedown breaks the chain. The practical consequence, the report argues, is that blocking lure domains is close to worthless as a control.
Targeting is server-side and per-visitor. The lure page reports the visitor's operating system, and the operator replies with a configuration naming which platforms to attack. In the sample analyzed, Windows was active, macOS landing pages were fully built and functional, Linux was empty, and mobile was suppressed. The payload is also gated on machine identity: a hardware and account fingerprint is encoded into the download path, so the command-and-control server sees the victim before serving anything. Sandboxes can be served a clean page or machine-specific content that is not the real payload, making detonation-based verdicts structurally unreliable.