By NHI Mgmt Group Editorial TeamBased on Push Security: “The most advanced ClickFix yet?” (November 6, 2025)

TL;DR: ClickFix has become a dominant initial access method, with Microsoft reporting it accounted for 47% of attacks in the last year, while Push Security shows the lures are evolving across page design, delivery channels, and payload execution. Endpoint-only interception is now a single point of failure, especially where browser-based code execution and unmanaged devices are in scope.


At a glance

What this is: This analysis shows how ClickFix lures are evolving into browser-delivered social engineering that persuades users to run malicious code locally, while detection and blocking increasingly depend on controls beyond the endpoint.

Why it matters: It matters because identity and security teams cannot assume email filters or EDR alone will catch user-initiated code execution when the attack starts in the browser and targets cookies, credentials, and unmanaged devices.

By the numbers:

  • 47% of attacks started with ClickFix in the last year, according to Microsoft.

Context

ClickFix is a browser-mediated social engineering pattern that tricks a user into copying and running malicious commands on their own device. The governance gap is that many security programmes still assume dangerous execution begins at email delivery or at the endpoint, while this technique starts earlier in the browser and often outside those monitoring assumptions.

Push Security argues that the lure, delivery path, and payload are all evolving at once. That means the defensive problem is no longer a single malicious page or single malware family, but a browser-to-endpoint attack path that can bypass email-first controls, evade inspection, and reach credentials stored in the browser.

For IAM and NHI teams, the important issue is not just malware execution. The deeper concern is that browser-stored session material and credentials sit in the same trust boundary as user interaction, so a socially engineered paste event can become an identity compromise path before endpoint controls even classify the action.


Key questions

Q: What breaks when ClickFix is not blocked before the user runs the command?

A: The failure is that the malicious action has already crossed from browser deception into local execution. At that point, the attacker can trigger payload delivery, steal browser session material, and evade controls that only inspect email or later host activity. Security teams need to treat pre-execution browser intervention as the real control boundary.

Q: Why do ClickFix attacks bypass many traditional phishing controls?

A: They often arrive through search, malvertising, or compromised websites rather than email, so email-centric filters never see them. Because the lure is delivered in a browser and the code is pasted locally, the attack can evade the security stack that assumes suspicious activity will originate from email attachments or links.

Q: What are the signs that browser-based copy-and-paste attacks are bypassing controls?

A: A practical signal is when suspicious web activity is followed by local command execution and then identity anomalies from the same user or device. Repeated access through search results, malvertising, or fake verification pages is another clue. Teams should correlate browser events, endpoint alerts, and session use instead of reviewing them separately.

Q: How should teams respond when endpoint controls are the last line of defence for browser attacks?

A: They should not treat endpoint controls as sufficient on their own. The better approach is layered enforcement that includes browser-layer detection, visibility into unmanaged devices, and identity monitoring for stolen cookies or session reuse. The goal is to stop the attack before local execution creates an account compromise path.


Technical breakdown

Why ClickFix defeats email-first monitoring

ClickFix is effective because it moves the attacker-controlled interaction into the browser and away from the classic email attachment or link click model. The lure can be delivered through search poisoning, malvertising, compromised sites, or email, but the decisive step is the user-initiated paste or command execution that happens after the page loads. At that point, email scanners and web-crawling controls may already have lost visibility, and the browser sandbox obscures the malicious clipboard action from many host and network tools.

Practical implication: stop treating email inspection as the primary control boundary for copy-and-paste execution lures.

Why endpoint-only interception becomes a single point of failure

The article shows that many ClickFix payloads only become visible when the command is executed locally, which pushes detection to EDR after the user has already complied. That makes endpoint-only defence fragile, especially where unmanaged BYOD devices, misclassification of user-initiated activity, or browser-based execution paths reduce the chance that EDR will see enough context to block decisively. In identity terms, this is a control-plane problem: the malicious action is triggered by the user, but the abuse target is often stored browser credentials, cookies, or authenticated sessions.

Practical implication: add browser-layer detection so the first enforcement point is before local execution begins.

How payload evolution widens the identity attack surface

Attackers are not relying on a single executable path. The article notes use of PowerShell, mshta, other LOLBINs, and cache-smuggling style techniques that reduce web requests and complicate inspection. That matters because each variation changes where policy can be enforced and which telemetry exists for triage. When the payload chain can be altered faster than blocklists or signature-based controls, the defensive problem shifts from blocking one binary to governing how browser activity becomes local execution and then identity theft.

Practical implication: map ClickFix coverage across browser, endpoint, and identity telemetry instead of assuming one control layer is enough.


Threat narrative

Attacker objective: The attacker wants the victim to execute malicious code and expose browser-resident identity material that can be reused for account compromise.

  1. Entry occurs through poisoned search results, malvertising, compromised sites, or email that leads the victim to a ClickFix page.
  2. The victim is socially engineered into copying and executing malicious code, often through an embedded video, timer, or fake verification flow.
  3. The payload runs locally through tools such as PowerShell or mshta, then the attacker seeks browser-stored credentials, cookies, or other session material.
  4. Impact is credential theft, session abuse, and a widened foothold that can bypass email-only and endpoint-only defences.
  • Meta Muse agent hijack 2026: An undocumented Muse setting let local malware hijack Meta's personal AI agent, steal its authentication material and abuse user access.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

ClickFix is really a browser-layer identity problem, not just a malware problem. The article shows that the attacker’s real leverage is the moment user trust inside the browser turns into local execution. That shifts the centre of gravity away from email filtering and toward the identity material already present in the browser session. For practitioners, the control boundary has to move closer to where the user is asked to act.

Endpoint-only defence is now an assumption, not a strategy. The article’s core warning is that organisations are left with a single late-stage interception point if they rely on EDR alone. That assumption breaks down when browser-delivered lures, unmanaged devices, and user-initiated commands reduce the chance of consistent endpoint visibility. The implication is that execution controls need a browser-aware layer, not merely better host telemetry.

Malicious copy-and-paste creates an identity blast radius. Once the user runs attacker-supplied code, the browser session becomes the bridge to cookies, credentials, and authenticated access. That is why ClickFix should be analysed alongside identity and session protection, not only malware prevention. The practitioner takeaway is that the relevant blast radius is the account and session boundary, not just the device.

Browser-delivered attacks are collapsing the separation between social engineering and access abuse. The article shows a modern pattern in which the social layer, delivery layer, and execution layer are chained together before traditional controls can react. That matters for IAM teams because the abuse target is often an authenticated session rather than a password alone. The implication is that browser governance now belongs in identity security planning.

Named concept: browser-to-endpoint trust collapse. ClickFix succeeds when the browser becomes both the social-engineering venue and the launch point for local execution, while defenders still assume those layers are separable. That assumption no longer holds in unmanaged or lightly managed environments. Practitioners should treat browser trust as part of identity attack surface management, not as a UI concern.

What this signals

Browser-to-endpoint trust collapse: ClickFix shows that the browser is now part of the execution chain, not just the delivery surface, so identity security needs to account for user actions that become local code before the endpoint can mediate them.

If browser-stored sessions and credentials are in scope, then detection has to move left of host execution. That means policy, telemetry, and response planning should connect the browser, the endpoint, and the identity layer as one attack path rather than three separate tools.


For practitioners

  • Instrument browser-layer blocking for copy-and-paste lures Detect and block malicious clipboard-driven execution before the command reaches the host, especially on pages that simulate verification, support, or security checks.
  • Review coverage for unmanaged and BYOD devices Map where EDR visibility is incomplete and identify users who can reach web pages but operate outside managed endpoint policy.
  • Correlate browser session theft with identity telemetry Watch for cases where a user-run command is followed by unusual cookie, token, or session use from the same identity.
  • Reduce reliance on email as the sole delivery control Assume ClickFix and similar lures will arrive through search, advertising, and compromised web properties, not only messages.

Key takeaways

  • ClickFix is evolving into a browser-delivered execution pattern that turns user trust into local code execution and identity exposure.
  • The article’s evidence points to a defence gap created by overreliance on email controls and late-stage endpoint interception.
  • Practitioners should add browser-layer detection and correlate session activity with endpoint telemetry to reduce the blast radius of browser-driven attacks.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIClickFix turns human browser interaction into misuse of code execution paths and identity material.
Recommendation — Treat browser-delivered copy-and-paste attacks as human-assisted NHI abuse and block them before execution.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe attack abuses authenticated browser sessions and identity material already present on the device.
Recommendation — Limit the permissions exposed in browser sessions and reduce the value of stolen cookies or tokens.
CIS Controls v8CIS-5 — Account ManagementSession abuse and account compromise follow once the attacker obtains usable identity material.
Recommendation — Review account and session governance to shrink the blast radius of browser-based credential theft.
MITRE ATT&CKTA0006;TA0002 — Credential Access; ExecutionThe attack chain moves from social engineering into local execution and then credential or session capture.
Recommendation — Map ClickFix detections to execution and credential-access tactics so triage reflects the real attack path.

Key terms

  • ClickFix: A browser-delivered social engineering technique that persuades a user to paste and execute a malicious command, usually through clipboard manipulation and a fake instruction sequence. The key risk is that the endpoint may see a normal user action even though the payload originated from a hostile webpage.
  • Browser-layer enforcement: Browser-layer enforcement is the ability to apply a security control directly inside the browser session where the risky behaviour occurs. It can block credential entry, interrupt suspicious consent flows, or contain the session before abuse spreads into downstream identity systems.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Session Material: Session material is the data that keeps an authenticated browser session alive, such as cookies, bearer tokens, and other reusable authentication artifacts. In NHI governance, session material matters because stealing it can bypass password and MFA controls without needing the original login flow.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org