And the Winner in Dominant Malware Delivery? ClickFix

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

ClickFix, a social engineering technique first observed in 2024, has become the dominant malware delivery method according to ReliaQuest research covering March–May 2026. The tactic tricks users into copying and pasting malicious commands into system dialogs, bypassing traditional file scanning and email defenses. Key findings include ClickFix expanding to macOS via applescript:// links that bypass Apple's Terminal paste warnings, attackers using AI-generated obfuscation in loaders like 'Deepload', and a notable shift toward targeting developers via malvertising campaigns impersonating tools like 'claude code install' and 'homebrew install'. In confirmed cases, exposed npm and Bitbucket tokens were found on compromised developer machines. ClickFix now accounts for nearly 28% of defense-evasion activity and is evolving into a modular post-exploitation launchpad. Defenders are advised to train users, simulate lures, and monitor for anomalous command sequences rather than blocking developer tools outright.

5m read timeFrom darkreading.com
Post cover image
Table of contents
ClickFix Attackers Go "Atomic" With ObfuscationClickFix Attackers Targeting Developers
88 Impressions