[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fs07WyIpPTOs0Zs_vQxV_ZCh_N_rqKtwX0upPaml5pgo":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"3e3b8a9b-40e5-4091-887b-916effd47402","Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones","threat-actors-don-t-want-better-attacks-they-want-repeatable-ones-6a32dc","The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting","The article highlights a shift in threat actor tactics, moving away from complex, novel attacks towards repeatable, standardized methods. Techniques like ClickFix, which leverages social engineering and existing system tools, are becoming prevalent. This approach, akin to a 'generics business' in the pharmaceutical industry, allows attackers to scale their operations by exploiting readily available vulnerabilities and pre-written exploit code, focusing on throughput rather than technical sophistication.","Threat actors prioritize repeatable attack methods over novel ones for scalability and efficiency.","Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones The Hacker NewsSep 01, 2026Social Engineering \u002F Endpoint Security The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting for 47% of the attacks in their notifications. Nothing arrives as an attachment, so there is nothing to scan. No vulnerability is used, so there is nothing to patch. What happens next is just as ordinary. When Bitdefender analyzed 700,000 security incidents, 84% of the high-severity ones involved binaries that were already on the machine - the same administrative tools your IT team uses every day. Nothing malicious was installed, because nothing malicious was needed. Neither technique is clever, but both are winning. And the reason is not that attackers have run out of ideas. It is that they are not looking for ideas. They are looking for something that works the same way at the next company, and the one after that. This is a business, and businesses standardize A criminal group that has to invent something new for every victim does not scale. One that has a procedure - a formula it can run against a list of targets, with predictable steps and a predictable result - can grow as fast as it can find targets. You can watch that preference in the data. Verizon’s most recent Data Breach Investigations Report makes the exploitation of vulnerabilities “the most prominent initial access vector in our dataset this year, reaching the height of 31%, up from 20% last year” - a 55% increase in a single year, in the one category that rewards scanning over skill. Edge devices are not popular because they are interesting. They are popular because the procedure is short enough to write on a card. Watch for new CVEs in internet-facing devices. Filter for the ones that give remote code execution and require no authentication - the easy ones. Then wait. Someone will publish a working proof of concept on GitHub, usually within days. When they do, scan the internet at scale and take whatever has not been patched yet. Notice what is absent from that procedure. Nobody in that chain develops anything. The exploit arrives free, from a researcher, on a public repository, on a schedule somebody else sets. The only capability required is the ability to run other people’s code quickly and at volume. Exposure becomes the selection criterion, and who the victim turns out to be stops mattering very much. There is a version of this in the legitimate economy. A generics manufacturer does not discover drugs. It waits for someone else’s research to become public, then produces a known formula at volume, competing on cost and speed to market rather than on invention. That is what this is. Not a research operation - a generics business, where the patent expires the day the proof of concept lands on GitHub. You can also see the preference in who wins. For more than a year, the top position on the ransomware leak-site rankings belonged to Qilin, which claimed roughly 1,600 victims across that span, usually more than a hundred a month. In June it was displaced by The Gentlemen, with 121 claimed victims against Qilin’s 80. These are figures the groups publish about themselves, so they are claims rather than audited numbers - but the two have been trading the top position, and what they are competing on is throughput. The leaderboard counts victims, it does not count technical achievement. The more telling detail is where the challenger came from. The Gentlemen branched out from a former Qilin affiliate, and as Bitdefender’s own threat debrief put it, they have demonstrated how successful ransomware “playbooks” are being recycled and improved. The procedure walked out of one organization and into another and worked just as well in new hands. That is the clearest available statement of what these groups actually own. Not an exploit, not a tool, not a secret. A method that can be written down, handed over, and run again. ClickFix is a playbook for getting in Look at ClickFix through that lens and its appeal is obvious. There is no payload to rebuild when a detection lands, because there is no payload. There is no exploit to re-develop when a vendor ships a patch, because no vulnerability is being used. When a lure stops working, you rewrite the text on a web page. The technique degrades gracefully, which is exactly what you want from something you intend to run thousands of times. It also works identically everywhere, because it does not depend on the target’s technology stack at all. It depends on a person being willing to follow instructions, and that is the one component present in every environment on earth, in the same version, with no patch available. The fact that it also removes every artifact a defense is designed to catch - nothing to scan, no exploit to detect, no signature to match - is a genuine advantage. But I would not put it first. Attackers did not choose this because it evades detection. They chose it because it repeats, and the evasion came free. Living off the land is the same idea, one step further in Initial access is just the beginning of the operation. The work that follows - the part that ends in stolen data or encrypted systems - runs on the same logic: a playbook that produces the same result wherever it is pointed. Only this time the tools are the ones already on the machine. Rather than bringing tooling of their own, they use what is already installed: the scripting engines, remote management utilities, archive tools and administrative binaries that ship with the operating system. That is what the 84% describes - those binaries were involved in the large majority of high-severity incidents we analyzed. The reason is not primarily stealth. It is that these tools are familiar, they are present in every environment, and - this is the part that matters - they are identical in every environment. An operator who learns the sequence once can run it at the next victim without adaptation. There is nothing to port, nothing that depends on the target’s build, and nothing that needs testing against an unfamiliar stack. Command and control follows the same instinct, routed through cloud services the organization already trusts and already permits. That these tools are also hard to distinguish from legitimate administration is a considerable bonus. It is not the reason they were picked. It is, however, the part defenders find hardest, and it is worth being honest about why. When an attacker introduces nothing, there is nothing to find. The economics look exactly like you would expect If cybercrime really is a volume business built on repeatable procedure, the financial picture should look like a volume business under pressure. And it does. Verizon’s most recent report has ransomware growing again, to 48% of all breaches, up from 44% the year before. Over the same period, the money moved the other way: 69% of ransomware victims didn’t pay, and the median ransom that was paid fell to $139,875 from $150,000. Bitdefender’s own tracking of ransomware leak sites counted 704 organizations claimed as victims in June 2026 alone. More victims, less money. That is falling revenue per attempt, and the rational response to falling revenue per attempt is not to make each attempt more elaborate. It is to make each attempt cheaper and more repeatable, and to run more of them. This is also where the AI argument meets arithmetic. The playbook approach costs an attacker close to nothing per attempt: the scanning is cheap, the exploit was free, and the tools were already installed on the victim’s machine. Putting a model in that loop adds a real cost to every attempt, in a busi","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fthreat-actors-dont-want-better-attacks.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgXRNAAGu1amxjm97oXzRGvVBD23d-thmuPvBbQm10hKlACH58ndu51swo4ggT2P2FJw1vbmWy6qdMZSyTRrgAXoi19O0Zf0vCcS47oMuhMuPSyKc1kL7bpIySVrQwgrIaYJkc4IiavU0rucYYMYWHwXgDCmsPLanV2LZv3mt__srP93r0vLWSz8Vp_L0o\u002Fs1600\u002Fclick.jpg","2026-09-01T11:30:00+00:00","2026-09-01T12:00:10.176888+00:00",7,[18,21,24],{"name":19,"type":20},"GitHub","product",{"name":22,"type":23},"Qilin","threat_actor",{"name":25,"type":23},"The Gentlemen","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":26,"icon":28,"name":29,"slug":30},null,"Threat Intelligence","threat-intelligence",[32,37],{"category":33},{"id":34,"icon":28,"name":35,"slug":36},"7d8b5ab8-ea0b-4ced-ae97-ec251b86993a","Ransomware","ransomware",{"category":38},{"id":39,"icon":28,"name":40,"slug":41},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[43],{"type":41,"value":44,"context":45},"ClickFix","Technique for initial access via social engineering and clipboard commands."]