AV TEST
  • Test Results
    • Home users
      • Windows Antivirus
      • MacOS Antivirus
      • Android Antivirus
    • Business users
      • Windows Antivirus
      • MacOS Antivirus
      • Android Antivirus
    • Internet of Things
    • IT security product overview
  • Articles
    • All news
    • Awards
    • Antivirus for Android
    • Antivirus for MacOS
    • Antivirus for Windows
    • Commissioned tests
    • Repair tests for Windows
    • Research
    • Internet of Things
    • Parental control
    • VPN tests
    • More tests
    • Other
  • Services
  • Press
  • About
    • Institute
    • Certification
    • Test procedures
    • Newsletter
    • FAQ
    • Jobs
  • Contact
    • Contact
    • Terms and conditions
    • Legal notice
    • Privacy policy

©  2026 AV-TEST  | SITS Deutschland GmbH

AV TEST AV TEST
  • Test Results
    • Home users
    • Business users
    • Internet of Things
    • IT security product overview
    • Windows Antivirus
    • MacOS Antivirus
    • Android Antivirus
    • Windows Antivirus
    • MacOS Antivirus
    • Android Antivirus

    Get in touch

    Please use the contact form below for inquiries to the AV-TEST Institute.

    Kontakt
  • Articles
    • All news
    • Awards
    • Antivirus for Android
    • Antivirus for MacOS
    • Antivirus for Windows
    • Commissioned tests
    • Repair tests for Windows
    • Research
    • Internet of Things
    • Parental control
    • VPN tests
    • More tests
    • Other
    Services

    Network Threat Protection -
    Tested and certified by AV-TEST

    LEARN MORE >

    Get in touch

    Please use the following contact form for inquiries to the AV-TEST Institute.

    Kontakt
  • Services
  • Press
  • About
    • Institute
    • Certification
    • Test procedures
    • Newsletter
    • FAQ
    • Jobs
  • Contact
    • Contact
    • Terms and conditions
    • Legal notice
    • Privacy policy
  • IOT-TESTS.ORG
  • AV-ATLAS.ORG

Latest News

October 09, 2026

Cybersecurity Awareness Month 2026: Phishing: the world’s leading cyberattack method

390 billion emails are sent globally every day, with nearly half of them being spam. Of these spam emails, approximately 3 to 5 percent are phishing emails, which corresponds to up to 9 billion emails – every day. Obviously, many of these will succumb to a provider’s diligent email filters or security solutions and be deleted long before they can end up in a user’s inbox. But if we suppose that even just 1 percent of these emails arrives in the recipient’s inbox, that translates into 90 million phishing emails on a daily basis.

Cybersecurity Awareness Month 2026:

Phishing: the world’s leading cyberattack method

Microsoft registered 8.3 billion threats stemming from phishing emails just in the first quarter of 2026. The experts at AV-TEST also collect spam and phishing emails on a daily basis and evaluate them in real time on their AV-ATLAS platform. It does not list the overall number, but records the different types of samples over a 7-day period. For example, more than 60 percent of 10,000 spam emails recorded contain a dangerous link and 30 percent have a malicious attachment. The rest of the spam emails are just annoying ads.

How people fall victim to phishing emails

It’s one of the oldest and yet most adaptive forms of cybercrime: phishing. The term originates from a combination of the words “password” and “fishing”, with cybercriminals using this attack method to “fish” for passwords and other valuable information. It’s based on a simple principle. The attackers pretend to be a trustworthy communication partner, while often preying on a user’s insecurity or claiming a false sense of urgency to react to something. They do so to manipulate their victims and coerce them into divulging login credentials, payment information or one-time codes. Increasingly, phishing attacks attempt to install malicious software or to grant first-time access to a corporate network. “Unfortunately many users are still being deceived by phishing emails. However, a good security software will quite often prevent the potential consequences of this negligence further down the road", says Igor Lückel, Head of Software Development at AV-TEST.

Generally, a phishing attack starts with an email. It might suggest that the recipient’s password for Microsoft 365 needs to be updated or that there is an outstanding bill or that a delivery attempt was unsuccessful. The email would include a link to a login page that looks deceptively authentic. But the person goes from user to victim the second they enter their username and password. That’s why a good security software for Windows, Mac or Android already provides adequate protection when these kinds of dangerous emails arrive in a user’s inbox. They either detect the threat immediately on receipt or they protect the user if an attempt is made to click the link or open an attachment containing malware.

Cybercriminals often don’t just stop at stealing a user’s password. Modern phishing websites now also ask users for a one-time code, which is used for two-factor authentication, enabling cyberattackers to log in with the second factor to access emails, cloud storage or internal applications. 

Phishing employs modern attack routes

Emails are the no. 1 inroad for cyberattacks. Nevertheless, attackers can also use other methods:

Smishing: In this type of exploit, the scammer sends a text message to the victim, purporting to be a delivery service provider, a bank or even their victim’s employer. It often contains a link to a fraudulent and dangerous website.

Quishing is a form of attack that uses QR codes. The QR code might be found in an email, on a printout, in a fraudulent letter or even on a manipulated flyer or poster. The victim scans the QR code on their phone and the dangerous link opens.

Vishing, short for “voice phishing”, involves the attacker calling the victim. The caller pretends to be a bank employee, IT support staff or a company executive. The goal of the call is to convince the victim to divulge passwords or authorization codes or even to install software for remote maintenance. The use of voice cloning and AI-generated calls makes vishing more convincing than ever. 

Spearphishing: This is a highly customized attack method that specifically targets high potential victims such as companies or prominent people. 

 

ClickFix – a particularly malevolent phishing scam

ClickFix is the latest social engineering technique plaguing Windows and Mac users. In contrast to traditional phishing, ClickFix does not rely on a manipulated webpage that tries to get the user’s password. Instead, it fakes a technical error, displaying a message about a failed security check, a browser error, a required software update or a CAPTCHA issue.

The webpage then instructs the user to “verify” a prompt by entering a series of keystrokes or copy-pasting a prewritten command. What the user is actually doing is executing a command for a malware on their Windows or Mac computer. This method is particularly devious as there is no typical email attachment, like in a traditional phishing scam, or perceivable download file.

A case from this past spring shows how serious the threat is. Microsoft documented a cyberattack campaign using ClickFix that targeted Windows users. Victims were tricked by a fake message about a security check through manipulated search results and compromised online ads. They were instructed to solve a verification issue by pasting a command into the Windows Run dialog box. But what they were actually doing was installing ACR Stealer, an infostealer. This, in turn, would export the passwords stored in the browser, session cookies, login tokens and personal documents. The attackers would sometimes disguise the malware as a software update. “A good security software can detect and even stop a ClickFix campaign; however, it doesn’t provide absolute protection. Users have to realize that they are the ones entering the commands manually and, in the process, convincing the system of the credibility of the commands. It’s the particular danger of a ClickFix campaign", explains Igor Lückel, Head of Software Development at AV-TEST

TerminalFix targets corporate networks

Igor Lückel
Igor Lückel
Head of Software Development of AV-TEST

The TerminalFix campaign is a new wave of attacks based on the ClickFix principle. It targets companies and the access points of their networks. The user here also will be shown a fake CAPTCHA prompt or Cloudflare challenge page on a compromised website. 

The Windows user is tricked into executing a prescribed command in the Windows terminal or in PowerShell. Even a tech savvy employee might be fooled into thinking that such a command is trustworthy, allowing more complex commands to execute.

At the end of August 2026, Microsoft examined a TerminalFix campaign that targeted a number of different companies across multiple industries. Once users executed the malicious PowerShell command, the attackers installed an infostealer and then launched the actual attack chain. The chain of exploits was designed to spy on the infected systems, identify internal infrastructure that could be accessed and set up an encrypted reverse-tunnel backdoor. This tunnel gives attackers a foothold across the company's network, enabling them to maintain persistent access via the compromised computer and lateral movement through the network. The German Federal Office for Information Security (BSI) had already issued warnings about a TerminalFix campaign directed at German institutions. Likewise, TerminalFix attacks pose a general threat to cybersecurity around the globe.

The AV-TEST lab looks at comparable scenarios in the course of its ATP tests, deploying alternating attack techniques by which infostealers and ransomware are surreptitiously loaded onto Windows systems.

Current
test results

  • Windows
  • MacOS
  • Android
  • Archive

  • Windows
  • MacOS
  • Android
  • Archive

  • Smart Home
  • IP-Cameras
  • Smart Watches
  • Other
Services

Network Threat Protection - Tested and certified by AV-TEST

Learn more
Services

Threat Intelligence Platform by AV-TEST

Start AV-ATLAS.org
Services

AV-TEST and the Cyber Resilience Act

Learn more

Subscribe to the AV-TEST Newsletter

Sign up now
Subscribe to the AV-TEST Newsletter
Sign up now
AV TEST

Get in touch

For inquiries to the AV-TEST Institute, please use the contact form below.

To the contact form

Sitemap

  • Institute
  • Test Results
  • Articles
  • Certification
  • Contact

Contact

  • SITS Deutschland GmbH
    Branch Magdeburg
  • Klewitzstraße 7
  • 39112 Magdeburg, Germany
  • E-Mail: info@av-test.com
  • Telefon: +49 391 6075460
  • Fax: +49 391 6075469

Terms and Conditions | Privacy policy | Legal Notice

©  2026 AV-TEST  | SITS Deutschland GmbH