Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Guides

ClickFix explained: the fake CAPTCHA trick

ClickFix pages ask you to paste a command to "prove you are human". Here is how the trick works and how to protect yourself and your staff.

By · Published · 9 min read

Two hands struggle to connect two irregularly shaped, mismatched puzzle pieces.

ClickFix has become one of the most common ways to spread malware. This month alone it was used to push the Psychedelic Stealer on hacked Ukrainian websites, a new Mac crypto stealer and the Lunex stealer.

How ClickFix tricks you into infecting your own device

  1. You visit a website — sometimes a real one that has been hacked.
  2. A box appears that looks like a CAPTCHA or a Cloudflare check.
  3. When you click, a malicious command is secretly copied to your clipboard.
  4. The page tells you to "verify" by pressing Win+R (Windows) or opening Terminal (Mac), then pasting and pressing Enter.
  5. You have just installed malware yourself.

Where ClickFix came from and how fast it has grown

Security researchers first documented ClickFix-style attacks in early 2024, with Proofpoint noting that the technique was initially used by the initial access broker TA571 and a fake-update compromise cluster known as ClearFake [[2]](https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape). By November 2024, Proofpoint reported the technique had become "much more popular across the threat landscape," with threat actors impersonating software such as Microsoft Word and Google Chrome to make the fake prompts look legitimate [[2]](https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape).

The growth has continued sharply since then. Microsoft said in August 2025 that it had observed ClickFix "growing in popularity, with campaigns targeting thousands of enterprise and end-user devices globally every day," and that it had helped customers across multiple industries address campaigns delivering payloads such as the prolific Lumma Stealer malware on both Windows and macOS devices [[1]](https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/). Security vendor Push Security's detection data shows ClickFix and its variants made up an average of 52% of its detections through the second quarter, a figure that climbed to 67% in August — more than any other browser-based attack technique, including adversary-in-the-middle phishing [[4]](https://pushsecurity.com/blog/the-state-of-clickfix-by-detection-data). Push Security also found that just three phishing kits — nicknamed ERRTRAFFIC, TURNTIP and NOCHAIN — accounted for 73% of ClickFix detections, with ERRTRAFFIC alone responsible for 34% in August [[4]](https://pushsecurity.com/blog/the-state-of-clickfix-by-detection-data).

Not just criminals — nation-state hackers have adopted it too

ClickFix has spread beyond financially motivated cybercriminals. Proofpoint found that over just a three-month period from late 2024 through early 2025, state-sponsored hacking groups linked to North Korea, Iran and Russia were all observed using the ClickFix technique for the first time in their routine operations, typically replacing earlier installation steps in their existing infection chains rather than reinventing their campaigns from scratch [[3]](https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix). Researchers describe this as a broader pattern in which techniques developed by cybercriminals are regularly copied by state-backed groups once they prove effective.

The malware families delivered through ClickFix

Various malware strains have been distributed using ClickFix lures, including AsyncRAT, Danabot, DarkGate, Lumma Stealer and NetSupport, according to Infosecurity Magazine's coverage of Proofpoint's original research [[5]](https://www.infosecurity-magazine.com/news/clickfix-cyber-malware-rise/). More recent campaigns, as referenced in this month's reporting, have used the technique to deliver the Psychedelic Stealer on compromised Ukrainian websites, a newly identified Mac-targeting crypto stealer, and the Lunex stealer.

Why ClickFix works so well

Because you run the command, browser and email protections often do not step in — the malicious action is carried out by a legitimate system tool (PowerShell, the Run dialog, or Terminal) under the user's own authority, not by a file silently downloaded in the background. Microsoft has noted that ClickFix is effective precisely because it "relies on human intervention to launch the malicious commands," meaning a campaign using this technique "could get past conventional and automated security solutions" [[1]](https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/). Infosecurity Magazine similarly observed that the tactic "preys on users' desire to fix problems themselves rather than alerting their IT team or anyone else" [[5]](https://www.infosecurity-magazine.com/news/clickfix-cyber-malware-rise/). And people are used to completing odd verification checks, since CAPTCHAs and browser security prompts have become a routine, barely-noticed part of browsing the web.

The one rule to remember

No legitimate website will ever ask you to paste anything into the Run box, Terminal or PowerShell. If you see this, close the page.

If you already did it

  • Disconnect from the internet.
  • From a different device, change passwords for email, banking and any saved logins.
  • Move any crypto to a new wallet.
  • Have the computer checked or reinstalled.
  • Watch for follow-on signs of compromise, such as unfamiliar login alerts, unexpected password reset emails, or new browser extensions you did not install.

For businesses

  • Train staff on this specific trick, with screenshots, since recognizing the fake CAPTCHA prompt is often the single most effective defense.
  • Restrict access to the Run dialog and PowerShell for users who do not need them, using Windows Group Policy or endpoint management tools.
  • Monitor for the specific command patterns ClickFix uses, such as PowerShell being launched directly from the Run dialog shortly after a browser visits an unfamiliar site.
  • Keep browser and endpoint protection tools updated, since several vendors now build specific detections for the clipboard-hijacking behavior ClickFix relies on.

What readers should do

  • Treat any website that asks you to open Terminal, PowerShell or the Run dialog as an immediate red flag, regardless of how official it looks.
  • Never paste text into those tools unless you copied it yourself from a source you fully trust and understand.
  • If a CAPTCHA or "verification" prompt behaves unusually — for instance, asking you to press a keyboard shortcut instead of simply clicking checkboxes or images — close the tab.
  • Keep your operating system and browser updated, and consider security software that specifically flags ClickFix-style clipboard activity.
  • Report suspected ClickFix pages to your IT or security team, or to the hosting provider if it is a compromised legitimate website.

Sources

How ClickFix differs from older malware delivery methods

Traditional malware delivery often relies on tricking a victim into opening a malicious email attachment or downloading a file from a compromised site — actions that antivirus software and email filters have gotten reasonably good at catching. ClickFix sidesteps that defense entirely by never delivering a file at all. Instead, it delivers a short text command that the victim pastes and runs using a trusted, built-in operating system tool. Because the "malware" at that stage is just a string of text sitting in the clipboard, and because the tool executing it (PowerShell, Terminal, or the Run dialog) is a legitimate part of the operating system, there is often nothing unusual for traditional security software to flag until the command has already run and begun downloading or executing its actual payload.

Read next