CTIPilot
← Back to the live brief
HIGHexploitedNATOB2research

ClickFix now drives 52-67% of monthly browser-based-attack detections, delivered overwhelmingly through search engines rather than email, and rotates across 20+ trusted binaries to outpace endpoint rules

Push Security's detection data: ClickFix has become the default browser-borne attack, and most of it never touches an inbox

Analysis

Push Security's H2 2026 detection-data review reports ClickFix and its derivatives averaging 52% of its monthly browser-based-attack detections through Q2 2026, rising to 67% in August 2026, ahead of adversary-in-the-middle phishing and device-code phishing combined (Push Security, 2026-09-23). Three phishing kits, ERRTRAFFIC plus two Push-internal-named kits TURNTIP and NOCHAIN, account for 73% of ClickFix detections, with ERRTRAFFIC alone responsible for 34% in August. Four in five 2026 ClickFix payloads were reached through search engines (Google/Bing) rather than email, via compromised sites, malvertising and SEO poisoning, meaning the technique largely bypasses email security controls that assume a phishing message is the entry point. Push observed 84 distinct ClickFix command forms spanning more than 20 trusted system binaries (PowerShell, cmd, bash/zsh, mshta, rundll32, msiexec, pcalua, wmic, certutil, schtasks among others), a deliberate LOLBin-rotation strategy intended to outpace endpoint-detection rules keyed on any single binary; Push reports the main kits now read their configuration from a smart contract on a public blockchain (an "EtherHiding" technique observed across BNB Smart Chain testnet, Polygon, Base and Ethereum Sepolia, with most of the observed traffic on testnets) rather than from the page itself, so payload and lure are fetched at load time, can be rotated with a single blockchain transaction, and leave no hosting infrastructure for defenders to take down or block.

NCSC Switzerland maintains a live public advisory describing the same technique's fake-CAPTCHA delivery mechanism, reporting an increase in compromised websites, predominantly WordPress, that serve the ClickFix lure to visitors (NCSC Switzerland / BACS): direct confirmation that this is not a theoretical or foreign-only trend but one actively affecting home-region infrastructure the constituency's users may encounter through ordinary browsing.

Push notes that standard EDR guidance of baselining LOLBin activity and alerting on anomalies suffers a high false-positive rate for this technique class, because legitimate IT automation, MDM tooling and administrator scripts generate similar-looking process-execution telemetry to a ClickFix payload's own binary invocation.

Triage: the discriminator is not which binary runs but its parent-process lineage and trigger context: a LOLBin (PowerShell, mshta, rundll32, certutil, or any of the 20+ Push documents) launched with a paste-derived command line from explorer.exe or a browser process, following a user interaction with a fake CAPTCHA or verification prompt on a webpage, is the ClickFix pattern; the same binary launched from a scheduled task, an MDM agent, or an IT-administration parent process in the course of routine automation is the benign lookalike. Sequence and parentage separate the two; the binary alone does not.

Cited evidence

Through Q2, ClickFix made up an average of 52% of Push's detections, surpassing other browser-based attacks (predominantly AiTM and device code phishing) for the first time.

And in August, this figure reached 67%.

Push Security 2026-09-23

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.