08.08.26

What is ClickFix malware? A new social engineering threat explained

ClickFix malware is one of the sneakiest new social engineering threats because it tricks people into infecting their own devices. Instead of asking you to download a suspicious file, a fake website, CAPTCHA, error message, or “security check” tells you to copy and paste a command into your computer.

That command may look like a quick fix. In reality, it can install malware, steal passwords, or give hackers remote access.

What is ClickFix malware?

ClickFix is not a single malware family. It is a social engineering technique that convinces users to run malicious commands on their own devices. In Microsoft’s analysis of the ClickFix social engineering technique, attackers used fake prompts that instructed victims to copy, paste, and run commands in Windows Run, Windows Terminal, or PowerShell.

A ClickFix scam may appear as:

  • A fake CAPTCHA check
  • A fake browser error
  • A fake document verification page
  • A “connection problem” alert
  • A fake software update
  • A fake security certificate issue
  • A fake job portal or travel booking message

The scam works because the page makes the instructions feel routine and helpful.

How does a ClickFix attack work?

Most ClickFix attacks follow a simple pattern:

  1. You click a link or visit a compromised page
    The page may come from phishing emails, malicious ads, fake job posts, hacked websites, or search results.
  2. The page shows a fake problem
    The message may say your browser failed verification, your session expired, or your system needs a quick fix.
  3. The page tells you to copy and run a command
    The command may already be copied to your clipboard.
  4. You paste the command into Run, PowerShell, Terminal, or Command Prompt
    This step can download malware without you realizing it.
  5. The malware steals information or gives attackers access
    Microsoft reported that ClickFix campaigns have delivered payloads such as Lumma Stealer, which can lead to information theft and data exfiltration in its ClickFix threat research.

Why is ClickFix dangerous?

ClickFix is dangerous because it abuses human problem-solving. Most people want to fix small tech issues quickly. Scammers exploit that instinct.

A ClickFix attack can lead to:

  • Stolen passwords
  • Stolen browser cookies
  • Remote access malware
  • Infostealer infections
  • Account takeover
  • Banking fraud
  • Work account compromise
  • Identity theft
  • More malware downloads

In Microsoft’s report on a Booking.com impersonation campaign, attackers used ClickFix prompts to trick hospitality workers into launching commands that delivered credential-stealing malware.

How big is the ClickFix and phishing risk?

ClickFix usually starts with the same ingredients as phishing: trust, urgency, and a fake instruction. CISA’s phishing guidance notes that phishing topped the FBI’s 2024 list of the five most reported cybercrimes, with 193,407 complaints, in its advice on helping people avoid phishing scams.

That number matters because ClickFix does not need advanced hacking skills to succeed. It only needs one person to trust the wrong prompt.

How does this help someone become safer online?

Understanding ClickFix helps someone become safer online because it teaches one memorable rule:

Never paste commands from a website into your computer.

That habit protects you from fake CAPTCHA scams, malware downloads, password theft, fake browser fixes, and job-search scams. If a website asks you to open Run, PowerShell, Terminal, or Command Prompt, treat the request as suspicious until verified by a trusted expert.

How can you spot a ClickFix scam?

Look for these red flags:

  • A website asks you to press Windows + R
  • A page tells you to paste a command
  • A CAPTCHA requires more than clicking or selecting images
  • A “fix” asks you to open PowerShell or Terminal
  • The prompt appears after clicking an ad or email link
  • The message creates urgency
  • The website impersonates a trusted brand
  • The instructions feel too technical for a normal webpage

What should you do instead?

Use this quick safety checklist:

  • Do not paste commands from websites
  • Close the suspicious page
  • Do not call numbers shown in pop-ups
  • Update browsers from the official browser menu
  • Use official apps and websites directly
  • Run a trusted security scan
  • Ask IT or a trusted expert before running commands
  • Report phishing emails or malicious pages

If you already pasted a command, disconnect from the internet, run a full security scan, change passwords from a clean device, and turn on multifactor authentication.

ClickFix malware succeeds because it makes dangerous commands look like helpful troubleshooting. Slow down, question the prompt, and never run commands from a webpage unless you fully understand and trust the source.