Skip to content

Original statistics

The ClickFix Index

Six measurements of ClickFix activity, computed from this site’s own record, defined in full on the methodology, and published under CC BY 4.0.

Statistics as of
2026-08-29
Published campaigns
44
Indicators on record
1,359
Sources credited
15
Licence
CC BY 4.0

1 · Median observed domain lifetime

Not yet measurable

— · 177 domains carry both dates

Days between the first date any source we hold reports observing a domain and the most recent date any source or re-check did.

Read it as a lower bound: live hosts have no end date, and we observe on report dates rather than continuously. How it is computed.

25th percentile
0 d
75th percentile
0 d
Longest observed
4 d
Seen on one day only
97.7%

Most of the 177 domains carrying both dates were seen on a single date, so the median across them is zero. A zero there measures how seldom anyone has looked twice, not how long a domain lives, so we withhold it until re-checking moves it off zero.

2 · New ClickFix domains observed per week

Each domain is counted once, in the week it entered the record — not once per report that mentions it.

New ClickFix domains observed per weekWeekly count of ClickFix domains entering the ClickFixReport record, by the week of first observation, covering 52 weeks ending 2026-03-02.New ClickFix domains observed per week52 weeks to 2026-03-02 · 257 domains040801201601462025-03-102025-05-192025-07-282025-10-132025-12-222026-03-02The ClickFix Index · CC BY 4.0clickfixreport.com/clickfix-index
Week commencing Monday. The window covers at most 52 weeks and ends at the most recent week containing an observation, not at today.

The last 12 weeks, as numbers

New ClickFix domains observed per week, most recent 12 weeks
Week commencingNew domainsRelative size
2025-12-151
2025-12-220
2025-12-290
2026-01-050
2026-01-120
2026-01-190
2026-01-260
2026-02-020
2026-02-090
2026-02-160
2026-02-230
2026-03-02146

45 further domains were first observed before the window opens. 411 domains carry no first-observed date and are counted in no week.

3 · Lure-theme mix

The pretext the page uses to get a command pasted. A campaign can carry more than one, so the shares do not sum to 100.

lure theme recorded for 43 of 44 published campaigns · most common: Fake CAPTCHA verification

Lure-theme mix, by number of published campaigns
Lure-themeCampaignsShareRelative size
Fake CAPTCHA verification2046.5%
Fake browser verification challenge511.6%
Fake macOS utility or troubleshooting guide49.3%
Fake software download page49.3%
Fake error dialog24.7%
Fake software update notice24.7%
Fake video conference page24.7%
Invoice or payment pretext24.7%
AI tool impersonation12.3%
Fake Discord server verification12.3%
Fake document repair prompt12.3%
Fake secure drive portal12.3%
Fake security update notice12.3%
Fake video game download12.3%
Fake Web3 application12.3%
Fake Windows Update screen12.3%
Government agency impersonation12.3%
Hotel guest belongings12.3%
Internet and cable provider impersonation12.3%
Online marketplace impersonation12.3%
Pirated film streaming site12.3%
Spoofed Microsoft Office document12.3%
Tax authority impersonation12.3%
Technology company impersonation12.3%

4 · Target operating-system split

Which platforms each campaign was reported to target. A cross-platform campaign counts under every platform its sources name.

target OS recorded for 44 of 44 published campaigns · most common: Windows

Target operating-system split, by number of published campaigns
Target operating-systemCampaignsShareRelative size
Windows3681.8%
macOS1125%
Cross-platform12.3%

5 · Execution-mechanism mix

How the pasted command actually ran — the Run dialog, a terminal, a script host. Recorded as a label, never as a runnable string.

execution mechanism recorded for 40 of 44 published campaigns · most common: Windows Run dialog

Execution-mechanism mix, by number of published campaigns
Execution-mechanismCampaignsShareRelative size
Windows Run dialog2357.5%
PowerShell1947.5%
Clipboard injection1537.5%
Terminal paste (macOS)820%
mshta.exe717.5%
BITS transfer download25%
PNG pixel-data steganography loader25%
DLL sideloading12.5%
FileFix12.5%
finger.exe payload retrieval12.5%
Windows batch script12.5%
Windows Terminal paste-and-run12.5%

6 · Our own extraction error rate

The rate below is produced by a blind weekly audit and by nothing else: five already-published entries re-checked against their sources by a human with the original assessment hidden. We publish it whatever it says. No entry has been audited yet.

Measured error rate
not yet measured
Entries audited
Found wrong
Extractions refused
0

“Extractions refused” counts indicator rows a database trigger rejected because their exact string was not in the archived source, so a rising count means the constraint is working. How the audit works.

7 · Use these figures

All of it is CC BY 4.0. Quote the numbers, redraw the chart, sell the article — the conditions are attribution and the date the figures were computed, because they change.

Cite as

ClickFixReport, “The ClickFix Index”, dataset clickfix-index, retrieved 2026-08-29.

https://clickfixreport.com/clickfix-index

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.

Credit line for a chart or a screenshot

<a href="https://clickfixreport.com/clickfix-index">The ClickFix Index</a> — ClickFixReport, CC BY 4.0

Plain text: Source: ClickFixReport, The ClickFix Index, 2026-08-29 — clickfixreport.com/clickfix-index

There is no iframe embed: the chart is plain SVG in the page markup with its credit drawn inside, so screenshot it or rebuild it in your own house style.