Últimas noticias
09 de octubre de 2026
Cybersecurity Awareness Month 2026: Phishing: the world’s leading cyberattack method
390 billion emails are sent globally every day, with nearly half of them being spam. Of these spam emails, approximately 3 to 5 percent are phishing emails, which corresponds to up to 9 billion emails – every day. Obviously, many of these will succumb to a provider’s diligent email filters or security solutions and be deleted long before they can end up in a user’s inbox. But if we suppose that even just 1 percent of these emails arrives in the recipient’s inbox, that translates into 90 million phishing emails on a daily basis.
Microsoft registered 8.3 billion threats stemming from phishing emails just in the first quarter of 2026. The experts at AV-TEST also collect spam and phishing emails on a daily basis and evaluate them in real time on their AV-ATLAS platform. It does not list the overall number, but records the different types of samples over a 7-day period. For example, more than 60 percent of 10,000 spam emails recorded contain a dangerous link and 30 percent have a malicious attachment. The rest of the spam emails are just annoying ads.
How people fall victim to phishing emails
It’s one of the oldest and yet most adaptive forms of cybercrime: phishing. The term originates from a combination of the words “password” and “fishing”, with cybercriminals using this attack method to “fish” for passwords and other valuable information. It’s based on a simple principle. The attackers pretend to be a trustworthy communication partner, while often preying on a user’s insecurity or claiming a false sense of urgency to react to something. They do so to manipulate their victims and coerce them into divulging login credentials, payment information or one-time codes. Increasingly, phishing attacks attempt to install malicious software or to grant first-time access to a corporate network. “Unfortunately many users are still being deceived by phishing emails. However, a good security software will quite often prevent the potential consequences of this negligence further down the road", says Igor Lückel, Head of Software Development at AV-TEST.
Generally, a phishing attack starts with an email. It might suggest that the recipient’s password for Microsoft 365 needs to be updated or that there is an outstanding bill or that a delivery attempt was unsuccessful. The email would include a link to a login page that looks deceptively authentic. But the person goes from user to victim the second they enter their username and password. That’s why a good security software for Windows, Mac or Android already provides adequate protection when these kinds of dangerous emails arrive in a user’s inbox. They either detect the threat immediately on receipt or they protect the user if an attempt is made to click the link or open an attachment containing malware.
Cybercriminals often don’t just stop at stealing a user’s password. Modern phishing websites now also ask users for a one-time code, which is used for two-factor authentication, enabling cyberattackers to log in with the second factor to access emails, cloud storage or internal applications.
Phishing employs modern attack routes
Emails are the no. 1 inroad for cyberattacks. Nevertheless, attackers can also use other methods:
Smishing: In this type of exploit, the scammer sends a text message to the victim, purporting to be a delivery service provider, a bank or even their victim’s employer. It often contains a link to a fraudulent and dangerous website.
Quishing is a form of attack that uses QR codes. The QR code might be found in an email, on a printout, in a fraudulent letter or even on a manipulated flyer or poster. The victim scans the QR code on their phone and the dangerous link opens.
Vishing, short for “voice phishing”, involves the attacker calling the victim. The caller pretends to be a bank employee, IT support staff or a company executive. The goal of the call is to convince the victim to divulge passwords or authorization codes or even to install software for remote maintenance. The use of voice cloning and AI-generated calls makes vishing more convincing than ever.
Spearphishing: This is a highly customized attack method that specifically targets high potential victims such as companies or prominent people.
ClickFix – a particularly malevolent phishing scam
ClickFix is the latest social engineering technique plaguing Windows and Mac users. In contrast to traditional phishing, ClickFix does not rely on a manipulated webpage that tries to get the user’s password. Instead, it fakes a technical error, displaying a message about a failed security check, a browser error, a required software update or a CAPTCHA issue.
The webpage then instructs the user to “verify” a prompt by entering a series of keystrokes or copy-pasting a prewritten command. What the user is actually doing is executing a command for a malware on their Windows or Mac computer. This method is particularly devious as there is no typical email attachment, like in a traditional phishing scam, or perceivable download file.
A case from this past spring shows how serious the threat is. Microsoft documented a cyberattack campaign using ClickFix that targeted Windows users. Victims were tricked by a fake message about a security check through manipulated search results and compromised online ads. They were instructed to solve a verification issue by pasting a command into the Windows Run dialog box. But what they were actually doing was installing ACR Stealer, an infostealer. This, in turn, would export the passwords stored in the browser, session cookies, login tokens and personal documents. The attackers would sometimes disguise the malware as a software update. “A good security software can detect and even stop a ClickFix campaign; however, it doesn’t provide absolute protection. Users have to realize that they are the ones entering the commands manually and, in the process, convincing the system of the credibility of the commands. It’s the particular danger of a ClickFix campaign", explains Igor Lückel, Head of Software Development at AV-TEST
TerminalFix targets corporate networks

Igor Lückel
Head of Software Development of AV-TEST
The TerminalFix campaign is a new wave of attacks based on the ClickFix principle. It targets companies and the access points of their networks. The user here also will be shown a fake CAPTCHA prompt or Cloudflare challenge page on a compromised website.
The Windows user is tricked into executing a prescribed command in the Windows terminal or in PowerShell. Even a tech savvy employee might be fooled into thinking that such a command is trustworthy, allowing more complex commands to execute.
At the end of August 2026, Microsoft examined a TerminalFix campaign that targeted a number of different companies across multiple industries. Once users executed the malicious PowerShell command, the attackers installed an infostealer and then launched the actual attack chain. The chain of exploits was designed to spy on the infected systems, identify internal infrastructure that could be accessed and set up an encrypted reverse-tunnel backdoor. This tunnel gives attackers a foothold across the company's network, enabling them to maintain persistent access via the compromised computer and lateral movement through the network. The German Federal Office for Information Security (BSI) had already issued warnings about a TerminalFix campaign directed at German institutions. Likewise, TerminalFix attacks pose a general threat to cybersecurity around the globe.
The AV-TEST lab looks at comparable scenarios in the course of its ATP tests, deploying alternating attack techniques by which infostealers and ransomware are surreptitiously loaded onto Windows systems.
