ClickFix attacks infecting PCs and Macs are going viral
ClickFix social engineering attacks are spreading widely, delivering malware to Windows and macOS users by tricking them into running malicious terminal commands that bypass Gatekeeper.
BlueVoyant reports the Lorem Ipsum malware operation pivoted to ClickFix in late May 2026, dropping code-signing infrastructure and broadening its victim pool from Microsoft Teams searchers to anyone browsing a compromised website. Jamf and independent researchers documented macOS ClickFix variants that bypass Gatekeeper protections. Cisco Talos observed attackers abusing published Google Sheets for control traffic, while Netskope counted 5,400 sites beaconing to one campaign; Sandworm has separately hosted control infrastructure in blockchain smart contracts.
- Lorem Ipsum operation adopted ClickFix in late May 2026, eliminating code-signing requirements
- macOS ClickFix variants documented by Jamf can bypass Gatekeeper protections
- Netskope counted 5,400 sites beaconing to one ClickFix campaign's infrastructure
- Attackers abuse Google Sheets and blockchain smart contracts for command-and-control
- BlockBlock and uBlock can block ClickFix commands as soon as users paste them
Full article353 words · extracted from arstechnica.com · click to collapse
For the people behind the attacks, ClickFix makes their job much easier. A previous way the people responsible for installing malware tracked as Lorem Ipsum, security firm BlueVoyant said recently, required resource-intensive infrastructure, including SEO-manipulated and malvertised download portals, Microsoft-trusted signing certificates, and continuously rotated domains for delivering Microsoft Installer packages.
“The pivot to ClickFix in late May 2026 eliminates the code-signing requirement entirely, substituting the legitimacy of a validly signed installer with a different form of legitimacy: a user voluntarily executing the malicious command in their own terminal,” BlueVoyant said. “While the ClickFix model broadens the victim pool from users searching specifically for Microsoft Teams to anyone browsing a compromised website,”
The situation for macOS users isn’t any better. Both Mac security firm Jamf and a researcher have documented macOS variations of ClickFix that can bypass Gatekeeper protections.
ClickFix attackers keep finding new ways to use public services—including publicly published Google Sheets documents, according to Cisco Talos. Other attackers, including Russia’s state-sponsored Sandworm, are hosting their control infrastructure in blockchain-based smart contracts. Security firm Netskope recently found another campaign that used the same approach. The security company counted 5,400 sites beaconing to it, an indication of the reach and scope of that campaign. And as OS makers and defenders build new defenses, attackers keep finding documented ways to work around them.
The upshot of all this is that ClickFix is a highly effective and efficient means of spreading all sorts of malware. It’s not going away, and victim-blaming or shaming only makes the problem worse.
There are a fair number of plugins, standalone products, and built-in defenses that are designed to blunt the success of ClickFix attacks. For instance, BlockBlock, the software that monitors Macs for processes that seek to permanently install themselves, can block ClickFix attacks as soon as a user presses the ⌘+V keys. Ublock has been updated to do something similar.
Beyond those fixes, those of us with more security training should build awareness with our less experienced neighbors, family members, and friends. The mass adoption of ClickFix demonstrates its success, and it’s not going away anytime soon.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2026/09/clickfix-attacks-infecting-pcs-and-macs-are-going-viral/