ClickFix: Emerging Favorite for Cybercriminals in Malware Delivery

New ReliaQuest research shows ClickFix drove nearly 28% of defense-evasion activity between March and May 2026, and it's now hitting macOS for the first time.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A computer screen displaying a fake error message with a prompt to paste a command, in an office environment
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • ClickFix drove nearly 28% of defense-evasion activity observed from March to May 2026.
  • ReliaQuest researchers recorded ClickFix attacks on macOS for the first time during this period.
  • Attackers shifted delivery from compromised websites to emailed links.
  • Developer-targeted malvertising exposed npm and Bitbucket tokens on compromised hosts.

ClickFix tricks people into copying and pasting malicious commands into system dialogs such as Windows Terminal or the macOS Script Editor, a built-in scripting tool. Fake error messages and CAPTCHA prompts supply those commands, bypassing file scanning and email defenses. ReliaQuest's analysis covers March 1 to May 31, 2026. We've followed this tactic in 33 stories over the past 90 days, starting 28 May 2026; our 18 June report detailed how attackers chained Google Ads and legitimate developer tools to steal session tokens and cloud credentials from that same population now appearing in this data.

Several variants have appeared in two years. "CrashFix" repeatedly crashes browsers and presents commands as a fix. Others use SEO poisoning through AI models to surface malicious links.

How did the hackers get in?

Criminals shifted from compromised websites to emailed links, a move that theoretically helps defenders: emailed lures travel through mail gateways where sandboxing can catch them. Traditional fake CAPTCHA prompts on Windows stayed active regardless. On macOS, phony software installation guides appeared alongside a new applescript:// delivery method.

ReliaQuest observed AMOS (Atomic macOS Stealer) deployed via applescript:// links that open Script Editor automatically, sidestepping the paste-warning Apple added in macOS 26.4. That warning triggers on Terminal but not on Script Editor. "Training, detection, and triage for it should run continuously on both Windows and macOS," ReliaQuest's Raigridas Bartkus wrote in the blog post.

Developer-targeted malvertising via Google Ads, most commonly fake "claude code install" and "homebrew install" results, presented error lures and instructed victims to paste commands. "The developer-targeted malvertising stands out as the highest-risk variant given the population it reaches," a ReliaQuest spokesperson told Dark Reading, citing exposed npm and Bitbucket tokens found on compromised hosts.

ReliaQuest also highlighted a ClickFix loader built to deliver "Deepload" malware, likely using AI-generated obfuscation to bury logic under thousands of variable assignments. That makes new variants faster to produce and signatures slower to write.

Should you worry about your macOS systems?

Yes, if you haven't extended Windows-grade monitoring to macOS. ReliaQuest recommends training staff on both platforms to refuse paste-into-terminal prompts, and running simulated ClickFix lures so employees recognise them under pressure. Blocking Terminal and Script Editor outright isn't feasible for developers. "The better approach is to log and alert rather than block," the ReliaQuest spokesperson told Dark Reading, flagging sequences of base64 decoding, curl retrieval and PowerShell or osascript execution as reliably anomalous.

The shift that matters most here isn't the macOS expansion: it's ClickFix behaving less like a delivery method and more like a post-exploitation platform, conducting domain enumeration and establishing persistent access without ever dropping a file.

© 2026 Threat Vectr