A new malware campaign dubbed ClickFix is rapidly spreading across PCs and Macs, leveraging social engineering and bypassing security measures. The campaign's efficiency has led to widespread adoption by attackers, making it a persistent threat.

The viral spread of ClickFix malware, which bypasses traditional security measures and leverages user actions, poses a significant risk to individuals and organizations by enabling widespread distribution of various malware types.
A rapidly spreading malware campaign known as ClickFix is infecting both PCs and Macs, exploiting user trust and bypassing security measures. The attackers behind ClickFix have found efficient methods to distribute their malicious payloads, making the campaign highly effective and persistent.
According to security firm BlueVoyant, the ClickFix model, which emerged in late May 2026, eliminates the need for resource-intensive infrastructure previously used for malware distribution, such as SEO-manipulated download portals and Microsoft-trusted signing certificates. Instead, it relies on users voluntarily executing malicious commands in their own terminals. This shift broadens the potential victim pool beyond users specifically searching for applications like Microsoft Teams to anyone browsing a compromised website.
macOS users are also vulnerable, with variations of ClickFix documented by Mac security firm Jamf and an independent researcher that can bypass Gatekeeper protections. Attackers are leveraging publicly available services, including Google Sheets documents, to host their operations, as noted by Cisco Talos. Furthermore, some campaigns, including those by Russia's state-sponsored Sandworm group, are utilizing blockchain-based smart contracts for their control infrastructure, a tactic also observed by Netskope in a campaign that saw 5,400 sites beaconing to it.
Security experts emphasize that as defenses are developed, attackers consistently find ways to circumvent them. Tools like BlockBlock and updated versions of Ublock are designed to mitigate ClickFix attacks by monitoring for persistent installations or similar malicious processes. The widespread adoption of ClickFix highlights its success and suggests it will remain a significant threat.