Executive Summary
In recent weeks, a social engineering attack known as "ClickFix" has been seeing widespread adoption across the threat landscape. ClickFix attacks are characterized by tricking users into manually executing malicious code on their own machines, by disguising the instructions as normal fixes such as CAPTCHA verification or other error messages. Because the user performs the action themselves, ClickFix bypasses many traditional email and download-based security controls. We recommend reviewing the awareness and technical guidance below with your teams.
What is Happening?
ClickFix is a fast-growing initial access technique in which attackers present the user with fake error messaging, CAPTCHA, or "verification" prompt on a compromised malicious website. The prompts instruct the user to copy a command and paste it into a Windows Run dialog, Powershell window, or terminal to "fix" the issue. However, the pasted command instead downloads and executes malware.
This technique has been adopted by a wide range of threat actors, from infostealers and RAT operators to ransomware affiliates and state-sponsored groups, simply because it is cheap to deploy, requires no software to exploit, is versatile in its deployment, and sidesteps defenses built around malicious attachments or downloads.

Example of ClickFix Lure with Copy, Paste, and Run directives
General Attack Flow
- Lure: User lands on a compromised legitimate site, malicious ad, or search result.
- Fake Prompt: A pop-up mimics a CAPTCHA browser error, or document-loading issue ("Fix this to continue").
- Instruction: The page tells the user to press Win+R (or open a terminal) and paste a provided command. In some cases, the command is placed into the user's clipboard without them seeing it and they simply need to paste.
- Execution: The user manually runs the command, which retrieves and executes a malicious payload.
- Payload: Commonly an infostealer, Remote Access Tools (RAT), or loader that establishes persistence and can lead to ransomware deployment.

Why Your Organization Should Care
- Since no file is downloaded or attachment is opened, traditional methods of malware defense, such as email security guardrails and download inspection rules may not trigger.
- The attack is primarily driven by effective social engineering. No exploit development is required, making the technical bar for entry very low.
- After the initial foothold is established, credential theft, data exfiltration, and ransomware deployment are frequently observed.
- Many industries can be targeted. Lures can be found in malvertising, compromised legitimate sites, and SEO poisoning.
Recommended Actions
- Train staff: Legitimate websites and software will never ask users to paste commands into Run, Powershell, or terminal windows.
- Encourage users to report unexpected "verification" or "fix it yourself" prompts.
- Restrict of log use of the Run dialog (Win+R) via Group Policy, where feasible.
- Enable Powershell Constrained Language Mode and enhanced logging.
- Deploy browser isolation or web filtering for high-risk ad/search categories.
For more information on how to protect your organization from cyber threats like ClickFix, please contact us below:
Managed IT Services | Move Your Business Forward Securely


