ADAMnetworks Launches ClickNix to Block ClickFix Attacks
ADAMnetworks, an industry leader in preemptive cybersecurity technologies, today announced the release of ClickNix, a free preemptive-security browser extension built to protect everyday internet users from ClickFix attacks — one of the most effective social engineering techniques used by cybercriminals today. ClickNix is available now at no cost to the community and works by denying ClickFix attacks the chance to ever present themselves to a user, stopping the attack before the moment of deception occurs.
Also Read: Forcepoint and BeyondTrust Link Identity Risk to Data Security
The ClickFix Problem
ClickFix has become one of the defining threats of the current attack landscape. Just recently joint research form ADAMnetworks & HudsonRock exposed the PasteSwitch campaign that used HBO Max’s official advertising account to deliver malware. Within 24 hours ADAMnetworks also tracked another major campaign where Brevo’s own infrastructure was used to deliver malware to victims using ClickFix techniques.
The technique uses a combination of Social Engineering (User Deception) and “Living off the Land” (LotL) techniques that defeats the standard Detection-Response based security that most of the current security tools rely on.
Attackers lure a victim with what looks like a routine step a CAPTCHA verification, a browser error message, a “fix this problem” prompt, or a fake meeting-software glitch and instructs them to open the Windows Run dialog, a terminal, or the Explorer address bar, paste a command, and press Enter. Because the victim executes the malicious command themselves, ClickFix sidesteps many of the email filters, antivirus signatures, and endpoint controls that organizations rely on to catch conventional malware.
The growth of this technique has been dramatic:
- Check Point’s 2026 Cyber Security Report independently confirmed roughly a fivefold increase in ClickFix activity, and researchers note the attack now spans Windows, macOS, and Linux alike, with ready-made “ClickFix builder” kits circulating among threat actors of every skill level.
- ADAMnetworks have witnessed this technique being adopted by all adversaries, from opportunistic infostealer and ransomware operators to nation-state-aligned groups, and new variants — including ones that fake a genuine browser crash to make the follow-on “fix” more convincing — continue to appear. In September 2026, ADAMnetworks’ research of currently infected sites exceeded 25,000 unique domains.
- Use of AI orchestration of malware campaigns allows for very fast attack infrastructure setup and elaborate evasion techniques implemented by attackers. Effective social engineering techniques like ClickFix are delivered with precision and stealth to remain undetected by current security systems on trusted websites and platforms.
Also Read: SuperCom Wins Two Texas Electronic Monitoring Contracts
ClickFix succeeds because it doesn’t rely on a technical exploit at all — it relies on trust. It hijacks a workflow people have been conditioned to see as safe: verifying you’re human, fixing an error, following an IT-style instruction. The victim isn’t tricked into clicking a bad link; they’re talked into infecting themselves, one paste and one keystroke at a time. That makes the attack nearly invisible to tools that are built to catch malicious files or known-bad URLs, because at the technical level, nothing “malicious” happens until the user acts on it.
“Exploiting the human means attackers are focusing their efforts on the weakest link in the security chain. But this relentless preying on vulnerable people is something we feel called to stop. ClickNix is an easy way we can help the world disrupt these attacks – especially for people who don’t have access to ZeroTrust connectivity yet,” says Francois Driessen COO & CMO of ADAMnetworks
How ADAMnetworks ClickNix Stops It
ClickNix is built on ADAMnetworks’ Preemptive Defense philosophy — an approach that disrupts attacks by design rather than detecting them after the fact. Instead of trying to recognize a ClickFix page once it’s already loaded and manipulating the user, ClickNix intervenes earlier in the chain, denying the deceptive page the ability to present itself to the user in the first place. If the lure never renders, the social engineering never has a chance to work — there is no fake CAPTCHA to trust, no “fix” instruction to copy, and no command for a victim to unknowingly execute.
When ClickNix identifies and denies a ClickFix attempt, it doesn’t stop there. Each blocked attempt is reported to a central threat-intelligence database, which other defenders security teams, MSPs, and ADAMnetworks Preemptive Defense customers can subscribe to. That means every ClickNix user strengthens protection for the rest of the network: an attack pattern intercepted for one person becomes protection for everyone downstream, often before that same campaign reaches them.
Also Read: SuperCom Wins Two Texas Electronic Monitoring Contracts
“ClickFix attacks are winning right now because it attacks trust, not code — and most of the security industry is still relying on detection of harmful code,” said ADAMnetworks CEO & Founder David Redekop. “Preemptive Defense is our answer to that: we don’t wait for the moment of the attack to happen and then try to catch it. We take the moment away. ClickNix takes the core of that philosophy and puts it directly into a browser extension that anyone can install for free, because this isn’t a threat that should only be handled by people who can afford enterprise security. It’s hitting regular people, at scale, every day.”
ADAMnetworks and their community partners also routinely check all the reported sites to confirm if the compromise has been rectified in order to let defenders know that it is safe to allow access to these sites again. So any website owner that became a victim of a ClickFix exploit on their site does not experience long-term disruption after they rectified the infection.
Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.