Back to News
Market Impact: 0.6

ClickFix Attacks Surge 517% in 2025

Cybersecurity & Data PrivacyTechnology & InnovationLegal & LitigationInfrastructure & Defense
ClickFix Attacks Surge 517% in 2025

Cybersecurity threats are rapidly evolving, with ESET reporting a 517% surge in ClickFix social engineering attacks in H1 2025, making it the second most prevalent vector and leading to diverse threats including ransomware, infostealers, and nation-state custom malware. Concurrently, the infostealer landscape has shifted dramatically, with SnakeStealer emerging as the dominant threat accounting for 20% of infections, while major law enforcement operations in May 2025 disrupted the infrastructure of prominent infostealers like Lumma Stealer and Danabot, despite their prior H1 2025 activity increases, signaling a dynamic and high-risk cyber environment for enterprises.

Analysis

The cybersecurity threat landscape demonstrated significant volatility and evolution in the first half of 2025, according to new research data. A social engineering attack vector known as ClickFix experienced a staggering 517% surge in the past six months, establishing it as the second most common attack method and accounting for nearly 8% of all blocked threats. This technique's effectiveness stems from its ability to bypass traditional security protections by manipulating users into executing malicious scripts themselves, a vulnerability that affects all major operating systems. The commoditization of this attack, with builders for weaponized landing pages being sold, suggests a low barrier to entry and portends continued growth. Concurrently, the infostealer market underwent a major reshuffle. SnakeStealer emerged as the dominant threat, comprising a fifth of all infections, while Agent Tesla's prevalence fell by 57% due to its operators losing access to its source code. This dynamic was further impacted by major law enforcement operations in May 2025, which disrupted the infrastructure of Lumma Stealer and Danabot, two platforms whose activity had grown 21% and 52% respectively in H1 2025 prior to the takedowns. This confluence of a rapidly scaling new attack vector and a shifting malware ecosystem points to a highly dynamic and elevated risk environment for enterprises.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

moderately negative

Sentiment Score

-0.50

Key Decisions for Investors

  • The rapid proliferation of ClickFix attacks highlights a critical gap in conventional security, creating a potential tailwind for cybersecurity firms specializing in user-centric security, such as security awareness training platforms and advanced endpoint solutions that focus on behavioral analytics.
  • Investors should anticipate continued volatility within the cybersecurity sector, as the rise and fall of specific malware families like SnakeStealer and Agent Tesla underscore the need for security platforms that are agile and backed by real-time threat intelligence rather than static defenses.
  • The broad impact of these threats across all operating systems suggests an increase in baseline cybersecurity spending across all industries, but also flags heightened operational risk for portfolio companies, necessitating a closer evaluation of their specific cyber-resilience and incident response capabilities.