AI Weekly Malaysia

Back to items Summaries

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

ID
28076
Status
summarized
Published
24 Sep 2026, 5:14 PM
Fetched
24 Sep 2026, 8:21 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.5
Created
24 Sep 2026, 8:22 PM
Tags
Audience
developersvibe_coderssaas_founders

What happened

CTM360's report traces ClickFix from a late-2023 novelty to what it calls the leading initial-access technique in enterprise intrusions, based on two analyses: a campaign-level set of over 17,000 URLs serving fake Cloudflare verification pages (roughly 3,000 still live at publication) and a host-level teardown of a single compromised WordPress site. The technique needs no exploit, attachment, or downloaded file — it writes a command to the clipboard and asks the user to paste it into a signed system binary themselves, which is why MITRE gave it sub-technique T1204.004 in March 2025 across Windows, macOS, and Linux. Cited telemetry: Microsoft attributed 47% of its Defender Experts initial-access cases in 2025 to ClickFix, and ESET measured a 517% rise into H1 2025 plus a further 108% between H2 2025 and H1 2026. The report also describes ClickFix as now operating as a subscription product with on-chain infrastructure and a state-sponsored user base, and argues domain blocking is no longer a useful defense.

Why it matters

If you run a public website — especially WordPress — you may be part of the delivery infrastructure rather than just a potential victim: the report's host-level analysis is of a compromised WordPress site serving the lure, and ~3,000 of the 17,000 fake Cloudflare verification URLs were still active. The practical decision is detection strategy, not blocklists: since the command is pasted by an authenticated user into a trusted signed binary, browser reputation checks, email gateway detonation, and domain blocking don't catch it, so the useful controls are clipboard-monitoring/EDR rules on the T1204.004 pattern and user-facing checks on your own site for injected fake-verification pages.

Discussion angle

The report claims blocking malicious domains is no longer a useful defense — so what would actually catch T1204.004 in a small team's stack, and is clipboard/EDR monitoring realistic for a team that ships a marketing site on WordPress?

Top