
Browser attacks in 2026: ClickFix, OAuth consent phishing and stolen sessions
A Push Security review of 2026 browser attack techniques shows how copy-and-paste lures, OAuth device-code phishing and session-stealing kits moved the whole attack chain inside the browser.
Push Security published a review of 2026 browser attack techniques, arguing the browser is now both the entry point and the end point of most intrusions. In the write-up, published by The Hacker News, Push's researchers say most breaches now begin inside a browser session and often never leave it, with the whole chain playing out there. Controls at the email, network and endpoint layers never see the decisive step.
ClickFix and the copy-and-paste lure
ClickFix became the dominant technique in Push's own detections for the first time, at 52% of total detections in the second quarter of 2026. The pattern has been known since late 2024: a fake CAPTCHA or verification page tells the visitor to copy a command and run it locally to fix a problem. Microsoft's Digital Defense Report had already named the technique the most common initial access vector, at 47% of observed attacks.
Four in five ClickFix payloads intercepted by Push arrived from search engines, through compromised sites, malvertising and SEO poisoning, so email security never sees them. InstallFix swaps the install command for a malicious one on malvertised fake install pages for tools such as Claude Code and NotebookLM. The LLMShare campaign delivered its malware through shared conversations on AI chatbot platforms, using pages hosted on trusted domains.
Authorization phishing after the login
A second family skips credential theft altogether. Authorization phishing abuses OAuth mechanisms, consent grants, device-code flows and token exchanges, to obtain access tokens without touching authentication, leaving multi-factor authentication, including phishing-resistant passkeys, with nothing to stop.
Push Security describes three variants. Consent phishing gets the victim to authorize a malicious third-party app through an OAuth consent grant. Device-code phishing abuses the RFC 8628 device authorization grant; Push tracks more than 30 distinct kits. ConsentFix, a ClickFix-OAuth hybrid first seen in Russian APT29 campaigns, has since been commoditized into criminal tooling.
Kits, sessions and the blocklist problem
Credential and session phishing is now sold as a service. Reverse-proxy adversary-in-the-middle kits such as Tycoon2FA, Sneaky2FA and Evilginx relay credentials and session tokens in real time, bypassing most forms of MFA, and ship with anti-bot protection and automated session replay. One in two phishing attacks is delivered outside email entirely, and 89% of phishing domains stay active for under two days, so blocklists cannot keep up.
Stolen session tokens extend the same problem: replaying a hijacked token in the attacker's own browser defeats passkeys, because authentication has already succeeded. Push ties that to infostealer malware, for which ClickFix is now a primary delivery mechanism, citing Verizon's DBIR 2025 finding that 46% of infostealer infections behind corporate breaches begin on unmanaged devices.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.