ClickFix Attack Technique Now Top Entry Point for Enterprise Breaches

A new report from CTM360 traces ClickFix from a novelty in late 2023 to a subscription product used by state-sponsored actors. The technique uses trusted websites to trick users into executing malicious actions without attachments or files on disk. Blocking malicious domains is no longer sufficient defense.
The shift from isolated scams to a commercialized, state-linked tool marks a significant evolution in social engineering. By abusing trusted websites, attackers bypass traditional email filters and file-scanning defenses, since no malicious payload ever touches the disk. This approach exploits user trust in familiar interfaces, turning routine web interactions into potential entry points. As threat actors adopt subscription-based models, the barrier to launching sophisticated campaigns drops, making such techniques accessible beyond elite hacking groups. Defenders must now focus on user behavior and browser-level controls rather than relying solely on domain blocklists.
This development could reshape how organizations approach endpoint security, as perimeter defenses alone may prove insufficient. Employees across all sectors—from finance to healthcare—may face increased risk of credential theft or ransomware, since a single click on a compromised trusted site could initiate a breach. Smaller firms without advanced threat hunting could be disproportionately affected, potentially widening the cybersecurity gap. Over time, this may accelerate adoption of zero-trust architectures and more aggressive browser isolation, though such measures could introduce friction into daily workflows.