17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
- ID
- 28076
- Status
- summarized
- Published
- 24 Sep 2026, 5:14 PM
- Fetched
- 24 Sep 2026, 8:21 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 24 Sep 2026, 8:22 PM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
CTM360's report traces ClickFix from a late-2023 novelty to what it calls the leading initial-access technique in enterprise intrusions, based on two analyses: a campaign-level set of over 17,000 URLs serving fake Cloudflare verification pages (roughly 3,000 still live at publication) and a host-level teardown of a single compromised WordPress site. The technique needs no exploit, attachment, or downloaded file — it writes a command to the clipboard and asks the user to paste it into a signed system binary themselves, which is why MITRE gave it sub-technique T1204.004 in March 2025 across Windows, macOS, and Linux. Cited telemetry: Microsoft attributed 47% of its Defender Experts initial-access cases in 2025 to ClickFix, and ESET measured a 517% rise into H1 2025 plus a further 108% between H2 2025 and H1 2026. The report also describes ClickFix as now operating as a subscription product with on-chain infrastructure and a state-sponsored user base, and argues domain blocking is no longer a useful defense.
Why it matters
If you run a public website — especially WordPress — you may be part of the delivery infrastructure rather than just a potential victim: the report's host-level analysis is of a compromised WordPress site serving the lure, and ~3,000 of the 17,000 fake Cloudflare verification URLs were still active. The practical decision is detection strategy, not blocklists: since the command is pasted by an authenticated user into a trusted signed binary, browser reputation checks, email gateway detonation, and domain blocking don't catch it, so the useful controls are clipboard-monitoring/EDR rules on the T1204.004 pattern and user-facing checks on your own site for injected fake-verification pages.
Discussion angle
The report claims blocking malicious domains is no longer a useful defense — so what would actually catch T1204.004 in a small team's stack, and is clipboard/EDR monitoring realistic for a team that ships a marketing site on WordPress?