HomeSecurity17,000 URLs reveal how ClickFix turns trusted websites into malware traps

17,000 URLs reveal how ClickFix turns trusted websites into malware traps

ClickFix has become the most common way attackers infiltrate corporate networks, and it does so without an exploit, attachment, or file on disk. The new global threat report traces the technique from a late-2023 innovation to a subscription product with on-chain infrastructure and a state-backed user base, and explains why blocking malicious domains is no longer a useful defense.

See also: ClickFix: Analysis of 3,000 payloads reveals API-driven malware

Article Image: 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
17,000 URLs reveal how ClickFix turns trusted websites into malware traps

A specific kind of security problem that no patch will fix. ClickFix is ​​one of them. The attack starts with a page that presents a problem that the user believes is theirs to solve. A human verification check that fails. A browser that can’t render the page. A document that won’t open. A Mac that’s running low on storage. The page offers a solution in the form of instructions, quietly writes the “fix” to the clipboard, and asks the user to open a system interface they already trust, paste it, and press Enter.

That's the whole technique. There's no vulnerability for a scanner to find, usually no attachment to explode from an email gateway, and no download for a browser reputation check to score. The command is pasted by an authenticated interactive user into a native, signed, globally present binary file, which is exactly the profile of the legitimate administrative job.

It is now the leading initial access technique in enterprise penetration telemetry. Microsoft attributed 47% of initial access cases handled by Defender Experts in 2025 to ClickFix, ahead of conventional phishing. ESET measured a 517% in the first half of 2025, and a further 108% between the second half of 2025 and the first half of 2026.

MITRE gave the behavior its own sub-technical, T1204.004, User Execution: Malicious Copy and Paste in March 2025, listing Windows, macOS, and Linux as affected platforms.

The report integrates two independent bodies of primary analysis with open source research: a campaign-level analysis covering more than 17,000 infected URLs serving fake Cloudflare verification pages, about 3,000 of which are still serving the bait at the time of writing, and a host-level analysis of a single compromised WordPress site examined entirely from the responses returned to a typical visitor. Taken together, they cover the full path from the injected page to an information stealer running inside a signed Microsoft process.

See also: ClickFix: 5,400 hacked websites use blockchain

ClickFix - SecNews.gr

The infrastructure is built to survive removal. The script injected into a compromised website does not contain any attacker domain. Instead, when a visitor loads the page, their browser makes a free, read-only call to a smart contract on blockchain . The contract returns an encoded string that decodes to the current decoy domain name. No wallet, no transaction, and no cost. The technique is known as EtherHiding.

During a single day of analysis, this contract returned three different bait domains in succession, and none of the compromised sites were modified. The operator processes a single on-chain value, and each infected site follows within seconds. There is no registrar to complain to, no hosting provider to notify, and the RPC providers used to read the value are legitimate shared services that real applications depend on.

The same architectural idea appears again further down the chain, where Telegram channel descriptions and a Steam profile page resolve the malware's command and control address. Two independent resolution mechanisms at two different stages is a design decision, not an accident: the kit is built so that no single removal will break it.

The practical consequence is inconvenient but clear. Blocking bait domains is almost useless as a control. They rotate faster than any block list that can be published.

See also: Over 250 ClickFix Domains Hide Malware Baits on macOS

Article Image: Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

The targeting is server-side, per-visitor, and intentionally hostile to analysis. The decoy page reports the visitor's operating system and version back to the handler, who responds with a configuration.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS