Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Social Engineering - The Most Advanced ClickFix Page Yet: What It Signals About the Future of Malicious Copy-and-Paste Attacks
Social Engineering Attacks Latest News News & Analysis Phishing

The Most Advanced ClickFix Page Yet: What It Signals About the Future of Malicious Copy-and-Paste Attacks

Kirsten DoyleBy Kirsten DoyleNovember 10, 20256 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
ClickFix Page
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

ClickFix attacks have exploded over the last year, evolving into one of the most effective forms of social engineering seen in the wild. By convincing users to copy and run malicious code on their own devices, bad actors have turned one of the oldest trust mechanisms in computing (copy-and-paste) into a weapon. 

At Push Security’s recent threat briefing in London, researchers showcased the most sophisticated ClickFix page observed to date. It’s a glimpse into how fast these attacks are developing, and how far they’ve come from crude proof-of-concepts just a year ago. 

A New Level of Deception 

The standout example was a Cloudflare-themed lure that could easily fool even the most cautious users. The page looks legitimate, a near-perfect imitation of a Cloudflare bot-check page, complete with an embedded instructional video, a live countdown timer, and a counter showing “verified users in the last hour.” Every detail is designed to amplify authenticity and urgency. 

Behind the slick design, the code is equally advanced. The page automatically adapts to the visitor’s device (serving tailored instructions for Mac users) and quietly copies malicious code to the clipboard through JavaScript. The victim believes they’re fixing a connection issue, but in reality, they’re launching a compromise. 

For years, awareness campaigns have told users not to click suspicious links or download random files. But few have been trained to question what happens when a trusted webpage asks them to open a terminal and paste in a command. That’s what makes ClickFix so effective: it hijacks muscle memory, not just judgment. 

Beyond Email: The New Delivery Frontier 

Unlike most phishing campaigns, the majority of ClickFix attacks aren’t coming through email at all. Push Security’s research shows that four in five intercepted ClickFix pages were reached via Google Search, through poisoned results and malicious advertising. 

Attackers are either compromising legitimate sites through hosting or CMS flaws or spinning up their own SEO-optimized clones. This shift away from email exploits a glaring blind spot in most security stacks. If your detection logic lives in the inbox, you’re already too late. 

Even when ClickFix pages are delivered by email, they’re hard to detect. Attackers rotate domains, use bot protection to block scanners, and obfuscate code to evade signatures. And because the malicious action happens inside the browser sandbox, traditional monitoring tools can’t see it. 

By the time endpoint protection gets involved, the user has already done the damage. 

Payloads That Push Boundaries 

ClickFix isn’t just evolving in delivery and design. Its payloads are diversifying, too. While PowerShell and mshta remain common, attackers are now abusing a broader range of legitimate binaries across operating systems. 

One emerging technique, known as cache smuggling, takes this even further. By caching a disguised file locally, attackers can execute malicious code without ever making a visible web request, effectively pulling malware onto the device under the radar of most network defenses. 

The logical next step? ClickFix campaigns that run entirely inside the browser, bypassing endpoint detection and response (EDR) tools altogether. 

The Numbers Tell the Story 

The 2025 Microsoft Digital Defense Report  revealed that ClickFix accounted for 47% of initial access attempts last year, nearly half of all observed attacks. For an attack technique that barely registered two years ago, that’s a seismic shift. 

The reason is simple: ClickFix collapses multiple stages of the kill chain into one. A single copy-and-paste action gives attackers the same level of access that once required a phishing link, a download, and a social engineering hook. 

The Real Risk: A Single Point of Failure 

For many organizations, EDR is now the only thing standing between a ClickFix attack and a full compromise. But EDR can’t be everywhere, particularly in environments where contractors and employees use unmanaged BYOD devices. When that final layer fails or misclassifies an alert, the attack slips through unnoticed. 

ClickFix is a shift in how social engineering works, from tricking users into giving up credentials to tricking them into executing commands. And as long as browsers and operating systems allow clipboard interactions by default, attackers will keep exploiting that trust boundary. 

Implications for Agentic AI 

Lionel Litty, CISO and Chief Security Architect at Menlo Security, says it’s  interesting that there is the potential that 80% of ClickFix attacks trace back to poisoned Google search results.  

“What’s really noteworthy is the implication for agentic AI. Agentic AI browsers (such as ChatGPT Atlas, Perplexity Comet, and standalone agents as well) are also liable to encounter this type of malicious prompt when performing tasks that involve visiting content found via Google searches. While these agents typically lack the ability to run commands, they can still be tricked into causing damage in many other ways, all while staying within the confines of the browser. It would not be surprising to see these attacks evolve to also target agents, just as we are seeing here that they have evolved to target multiple operating systems.” 

Defense in Depth 

James Maude, Field CTO at BeyondTrust, adds that the most modern cyber-attacks can be mitigated by the oldest of controls, least privilege and application control. “While EDRs can provide a line of reactive protection, this should be combined with the proactive protection of removing admin privileges and controlling application execution as part of a defense-in-depth approach. The fewer privileges the victim has, the lower the risk to the organization. If you can layer application control on top of that to prevent threat actors from downloading and launching malicious tools, that further reduces the risk.” 
   
The reduction of privileges doesn’t just apply to the endpoint as these types of malware are often harvesting credentials and session tokens for cloud and SaaS services, Maude says. “This means that any standing privilege that the user has on their endpoint, or in the cloud, could be exploited and used against them and their organization.” 

Getting Users to Compromise Themselves 

“All social engineering comes down to getting users to compromise themselves, and as attackers have to rely on more sophisticated methods beyond the grasp of typical users, they need to make it as simple as possible,” ends John Bambenek, President at Bambenek Consulting. “Explainer videos are a logical next step, especially given they are trivial to create with generative AI now.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Klue supply chain breach exposes Salesforce data at several security firms
  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Ad Fraud is Much More Than a Marketing Problem

March 6, 20265 Mins Read

AI Is Making Social Engineering Harder to Detect—But We’re Still Training People Like It’s 2015

March 5, 20266 Mins Read

Sextortion and the Psychology of Fear: How Scammers Are Targeting Teenagers

January 28, 20268 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}