ClickFix attacks infecting PCs and Macs are going viral

https://cdn.arstechnica.net/wp-content/uploads/2026/09/malware-infected-laptop-1152x648.jpg

For the people behind the attacks, ClickFix now makes their job much easier. Prior to ClickFix, they would have needed to install the malware (tracked as Lorem Ipsum, security firm BlueVoyant said recently) using resource-intensive infrastructure, including SEO-manipulated and malvertised download portals, Microsoft-trusted signing certificates, and continuously rotated domains for delivering Microsoft Installer packages.

“The pivot to ClickFix in late May 2026 eliminates the code-signing requirement entirely, substituting the legitimacy of a validly signed installer with a different form of legitimacy: a user voluntarily executing the malicious command in their own terminal,” BlueVoyant said. “[T]he ClickFix model broadens the victim pool from users searching specifically for Microsoft Teams to anyone browsing a compromised website.”

The situation for macOS users isn’t any better. Both Mac security firm Jamf and a researcher have​​documented macOS variations of ClickFix that can bypass Gatekeeper protections.

ClickFix attackers keep finding new ways to use public...

Copyright of this story solely belongs to arstechnica.com. To see the full text click HERE

Read more