Social Engineering Surge: ClickFix, AI Phishing, Device Code Phishing
Key Questions
How has the ClickFix technique evolved in 2026?
It grew 500% and is now used by APT28, Kimsuky, and MuddyWater groups. The method combines social engineering with automated credential theft. Defenders report increasing difficulty distinguishing it from legitimate user actions.
What makes AI-generated phishing so effective?
Emails cost only $0.04 each and achieve 54% click-through rates. AI enables personalized content at scale that bypasses traditional filters. Organizations must adopt advanced behavioral detection to counter this volume.
What is Device Code Phishing and why is it rising?
Attackers abuse Microsoft's device code flow to phish credentials without passwords. It targets the growing use of MFA and passwordless authentication. Only 28% of financial institutions currently use phishing-resistant MFA.
ClickFix technique grows 500%, adopted by APT28, Kimsuky, MuddyWater. AI phishing at $0.04/email with 54% click-through. New variants of ClickFix and MacSync Stealer reported. Microsoft Teams vishing using Quick Assist to deploy GoGRPC backdoor remains active. New: AI-Powered Email Threats article provides concrete stats (54% click-through, $3B BEC losses) and defensive strategies, reinforcing the urgency. Zero-day email threats article adds negative 7-day MTTE and 90 zero-days in 2025, linking email threats to the broader exploit window collapse.