The browser has become a primary target for cyberattacks due to its role in accessing business applications. Many breaches now originate and conclude within browser sessions, indicating a shift in attack methodologies.
Modern phishing kits, such as Tycoon2FA, Sneaky2FA, and Evilginx, are designed to intercept live sessions and bypass multi-factor authentication (MFA) by relaying credentials and session tokens in real time. These kits are available as Phishing-as-a-Service platforms, lowering the barrier for attackers.
Phishing delivery has expanded beyond email, with approximately half of all phishing attacks now delivered via instant messaging, social media, SMS, malicious ads, and in-app messaging. The short lifespan of phishing domains (active for less than two days) renders blocklist-based defenses ineffective.
Since late 2024, attackers have used a technique called ClickFix, which involves tricking users into copying and executing malicious commands under the guise of fixing an issue, such as a fake CAPTCHA. Microsoft's Digital Defense Report identified ClickFix as the most common initial access vector, accounting for 47% of observed attacks, and it became the dominant technique in Push detections in Q2 2026, reaching 52% of total detections.
ClickFix is a hybrid attack, with the lure delivered via the browser, but the user executes malicious scripts locally, often installing Remote Access Tools or infostealer malware. Four out of five ClickFix payloads intercepted by Push originate from search engines via compromised sites, malvertising, and SEO poisoning, bypassing email security entirely.
The ClickFix technique continues to evolve into variants like InstallFix, which uses malvertised fake install pages for developer tools where the install command is replaced with a malicious one. The LLMShare campaign delivered malware through shared conversations on AI chatbot platforms, using pages hosted on trusted domains.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Browser-based attacks are increasing, with phishing and malicious copy-paste (ClickFix) identified as leading threats. These techniques bypass traditional security measures by intercepting live sessions, using diverse delivery methods, and exploiting user actions to install malware.