Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

ClickFix Hijacks 17,000 Trusted URLs to Deliver Malware, Bypassing Traditional Defenses

CTM360 uncovered a subscription service, ClickFix, that repurposes over 17,000 reputable URLs into malware delivery points, requiring no exploit or attachment. The technique illustrates a supply‑chain risk that challenges domain‑blocking defenses and underscores the need for continuous third‑party monitoring for audit readiness.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
thehackernews.com

ClickFix Hijacks 17,000 Trusted URLs to Deliver Malware, Bypassing Traditional Defenses

What Happened – A CTM360 threat report identified a subscription‑based service called ClickFix that turns legitimate, high‑reputation websites into malware delivery points. The researchers cataloged more than 17,000 compromised URLs that silently redirect users to malicious payloads, requiring no exploit, attachment, or file on disk. The technique has been in active use since late 2023 and is supported by on‑chain infrastructure and a state‑sponsored user base.

Why It Matters for Trust & Control Assurance

  • Demonstrates how a third‑party web service can become a covert entry vector, undermining perimeter defenses that rely on domain blocking.
  • Highlights the need for continuous monitoring of external services and evidence‑based vendor oversight to satisfy control‑assurance objectives.
  • Directly maps to Verisq’s Vendor Risk Management capability, which provides real‑time attestations that third‑party services remain trustworthy.

Who Is Affected – Enterprises that rely on external web content, SaaS platforms that embed third‑party URLs, and any organization whose users browse the public internet from corporate devices.

Recommended Actions

  • Integrate automated URL‑reputation feeds and continuous monitoring of third‑party domains into your security stack.
  • Conduct a vendor risk assessment for any service that supplies URLs or redirects, documenting due‑diligence evidence for audit readiness.
  • Update incident‑response playbooks to include “malicious‑domain‑without‑exploit” scenarios and test detection controls.

Technical Notes – ClickFix operates as a subscription service that leverages compromised DNS records and on‑chain payment mechanisms to monetize malicious redirects. No known CVE is involved; the attack vector is a third‑party dependency that turns trusted domains into malware traps. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →