Push Security's detection data puts ClickFix at 52% of everything it caught through the second quarter and 67% in August. A Sophos post-incident report shows what one of those lures does to a freshly enrolled Mac in about two minutes.
Key Takeaways
The most effective intrusion technique of 2026 asks the victim to do the attacker's work. A ClickFix page shows a fake CAPTCHA, a broken-download notice, or an install instruction, then tells the visitor to paste a command into Run, PowerShell, or Terminal. No exploit fires and no malicious file has to land first, so the controls most organizations rely on to stop malware have nothing to inspect. New detection data shows the technique is no longer one lure among many. For at least one vendor it is now the majority of what gets caught.
Push Security's H2 2026 analysis, published September 23, reports that ClickFix and its derivatives averaged 52% of the company's detections through the second quarter and climbed to 67% in August. Push also cites Microsoft's figure of 47% of detections, which placed ClickFix as the top initial access vector. Three phishing kits, ERRTRAFFIC, TURNTIP and NOCHAIN, accounted for 73% of the ClickFix activity Push saw, and the largest is sold as a service for $300 to $380 a month.
The delivery route matters as much as the volume. Push says 4 in 5 ClickFix payloads it intercepted in 2026 were reached from search engines, through compromised sites, malvertising and SEO poisoning, and roughly half of the attacks it detected arrived through channels other than email. That puts the first contact outside the mail gateway, where most phishing investment has gone. The command itself is a moving target: Push logged 84 distinct command forms, 34 of which appeared only once, across more than 20 system binaries including PowerShell, curl, mshta and rundll32.
The compromised-site side of that pipeline is large and hard to see from outside. A CTM360 report published by The Hacker News on September 24 traced more than 17,000 URLs serving fake Cloudflare verification pages, around 3,000 of them still active at the time of writing. The injected script reads its current lure host from a Polygon smart contract, so one on-chain edit updates every infected site, and the operator's server sends sandboxes and crawlers a clean page. The same report cites ESET growth of 517% into the first half of 2025 and a further 108% between the second half of 2025 and the first half of 2026. The analyzed campaign delivered Vidar Stealer on Windows and had a macOS branch built and held in reserve.
Mac fleets are firmly in scope. Microsoft Defender researchers reported that since late 2025, macOS infostealer campaigns have used ClickFix-style prompts and malicious disk images to deliver DigitStealer, MacSync and Atomic Stealer, chaining native tools such as curl, base64, gunzip and osascript to harvest browser credentials, wallets and developer secrets. KELA's September analysis counted macOS infostealer infections rising from fewer than 1,000 in 2024 to more than 70,000 in 2025, still a small slice of an ecosystem that produced 347.5 million credentials from about 3.9 million infected machines overall.
What those stolen credentials unlock is the enterprise problem. In KELA's 2025 data, business cloud platforms made up 19.6% of compromised credentials, user authentication services 12.9% and version control systems 8.9%, and stolen session cookies and tokens can let an attacker move into cloud infrastructure without needing the password at all.
Sophos's own root-cause analysis of an incident on August 28 shows the sequence inside a security company. An employee setting up a new Mac searched for a desktop build of an AI assistant, clicked a sponsored ad that impersonated the vendor, and pasted the Terminal command the lure page offered. Between 06:22 and 06:24 UTC the payload collected keychain contents, browser and password-manager data, cloud and SSH keys and a developer access token, exfiltrated about 16.5 MB, installed a privileged LaunchDaemon and deleted its staging directory. The on-device antimalware was running and did not stop delivery, execution, persistence or exfiltration, because no malicious file was ever written for it to scan. Behavioral analytics in Sophos's managed detection service caught the activity inside the same window.
The detail most IT teams should take from the report is a gap in enrollment, not detection. Sophos's browser-based identity protection deployed automatically to Windows machines but required a manual group assignment on macOS, so the new laptop went without it. The endpoint was isolated at about 13:55, credentials and sessions were revoked by 15:00, and an enterprise-wide hunt found one affected host and no lateral movement. Push's data shows where that kind of access leads elsewhere: Halcyon has documented ClickFix as the delivery route for Qilin, Termite, Interlock and LeakNet ransomware, and one operator Push tracks has hit more than 30 victims since July, concentrating on healthcare.
ClickFix succeeds because it routes around file-based prevention and lands on whichever device is least configured. The response is less about a new product than about closing the gaps the technique depends on.
The technique is cheap, it changes its commands almost daily, and it hides its infrastructure from the scanners meant to find it. What it cannot easily get around is a device that was fully configured on day one and a credential that expires before anyone can sell it.
Guide
Sophos's breached laptop went without a protection that Windows machines received automatically. This guide sets out the Mac security baseline and automated compliance checks that catch a new device enrolled without its controls.
Download
Guide
A two-minute ClickFix theft yields cloud keys, SSH keys and session tokens. This guide sequences the identity and device posture work that limits what those stolen credentials can reach once they leave the endpoint.
Download
Guide
ClickFix is now a documented entry point for Qilin, Interlock and other ransomware crews. These five layered measures, from endpoint hardening to awareness training against social engineering, cover the gap a pasted command exploits.
Download
Comparitech counted a record 2,627 ransomware attacks in Q3 2026, but only 247 were confirmed by the organizations named.
Cisco Talos found authentication abuse in 65% of Q2 2026 engagements, nearly double the prior quarter.
Apple's September 2026 update fixed 273 unique vulnerabilities in one release, but closing a flaw across a fleet still takes months.