Back to advisories

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

ClickFix is now the leading initial access vector for enterprise intrusions, using social engineering to trick users into pasting malicious commands into legitimate system interfaces like PowerShell and Command Prompt. Attackers compromise websites and use blockchain infrastructure to host payloads, defeating traditional domain blocking. This technique bypasses most security controls because the execution happens from trusted system processes initiated by the user.

CRITICALAdvisorySep 26, 2026
Action required
Hunt for suspicious clipboard activity and script execution from PowerShell/cmd.exe following user interactions with web browsers. Monitor for process creation from these shells with command-line arguments containing encoded payloads, Base64 strings, or suspicious download commands. Check endpoint logs for paste operations into system consoles within 5 minutes of browser activity.
Affected products
CloudflareWordPressTelegramSteamMicrosoft Defender