ClickFix: an attack where you run the malware yourself

All it takes is a few clicks, copying a short command, and confirming its execution. That is exactly what ClickFix attacks rely on: the attacker convinces the user to run malicious code themselves. The entire process may appear to be a routine verification, update, installation, or a set of instructions for resolving a technical issue. In this article, we will show what ClickFix campaigns look like in practice, which techniques attackers use, and how to recognize this type of attack before it succeeds.

20 Sep 2026 Natalia Peterková

With fraudulent emails and websites, we are used to looking for suspicious links or attachments. ClickFix, however, is different. The attacker guides the user like a puppet: they create a seemingly trustworthy situation, apply pressure, and then tell the user step by step what to do. In this way, the user is persuaded to enter and execute a malicious command themselves, while believing they are simply following ordinary instructions or resolving a technical issue.

To achieve this, attackers often misuse common operating system tools, such as:

  • Run (a Windows tool for launching programs and commands),
  • PowerShell (a Windows command-line environment),
  • Terminal (a command-line environment in macOS).

ClickFix works by having a fraudulent website display instructions for resolving an alleged problem. A prepared command may be automatically copied to the system clipboard (where text is stored when using Ctrl+C). The user is then instructed to paste the command into one of the tools mentioned above and execute it. As a result, they may unknowingly download malware onto their device that can steal login credentials or enable remote control of the device. ClickFix can reach users through phishing, HTML attachments, malicious advertisements, or compromised legitimate websites.

No description

Why might I not recognize ClickFix immediately?

Because it takes advantage of actions we are used to performing almost automatically online.

Every day, we click through cookie notices, login prompts, verification requests, and various notifications, so we often perform similar actions automatically and without much thought. This “click fatigue” (click fatigue) can increase the likelihood that a user will continue following fraudulent instructions without noticing the warning signs in time.

What can ClickFix look like?

ClickFix does not have a single fixed form. The main difference lies in what attackers disguise their instructions as. It may appear as user verification, a technical issue, an update, an installation, or a problem with a document or online service. The way users are persuaded to follow the instructions may therefore vary, but the underlying principle of the attack remains the same.

1. Fake user verification

What does the attack look like?

A common form of ClickFix is fake verification, which imitates familiar elements from everyday internet use. A typical example is CAPTCHA.

At first glance, it looks like a standard “I’m not a robot” check. Instead of simply ticking a box, however, it displays a series of steps to follow.

Be careful!

A legitimate CAPTCHA takes place directly on the website, typically by ticking a box, selecting images, or completing another simple verification step.

If a supposed “I’m not a robot” verification asks you to continue outside the browser or to open Run, PowerShell, or Terminal, this is a clear warning sign.

Where has this variant appeared?

Booking.comattacks targeting hotel staff (2024–2025)

Attackers impersonated Booking.com and primarily targeted employees of hotels and other organizations in the accommodation sector. The fraudulent messages used situations that hotel staff commonly encounter, such as a new reservation, a negative review, a promotional offer, or a request to verify an account. After opening the link, users were shown a fake CAPTCHA. The campaign primarily aimed to steal login credentials and financial info and affected organizations across several regions.

2. Fake website and browser errors

Why might you encounter?

A warning or error message appears on the page and looks like a normal website or browser problem. It may claim, for example, that the content failed to load, a connection error occurred, or a “fix” is required.

The message may even imitate the appearance of the browser itself. It becomes suspicious when, instead of simply suggesting that you reload the page, it provides specific instructions for fixing the problem.

Be careful!

A normal browser error will usually ask you to reload the page, check your connection, or try again. If it instead provides an unusual “fix” or step-by-step repair guide, treat this as a warning sign.

A familiar browser design
or a trustworthy-looking web address does not,
by itself, guarantee that
the displayed
error message is genuine
.

Where has this variant appeared?

ClearFake / ClickFix fake errors on legitimate websites (2024)

Some of the first more prominent ClickFix campaigns appeared on compromised legitimate websites, where visitors were shown a fake browser error. Attackers later also imitated the familiar Google Chrome “Aw, Snap!” error page. A trusted website could therefore reduce users’ suspicion and increase the likelihood that they would see the displayed instructions as a genuine solution to the problem. These campaigns were primarily associated with financially motivated attacks and data theft.

3. Fake system updates and installations

How does the attack work?

The attack is disguised as a routine system update or the installation of a well-known application. The user is led to believe that they cannot continue without completing it.

The scam may imitate a Windows update or an application installation on macOS. It is often displayed in full-screen mode and hides browser controls.

Be careful!

A legitimate system update or application
installation will not ask you to
manually enter commands by following
instructions on a website.

Only install and update software
through the operating system, an official app store,
or the software vendor’s official website.

Where has this variant appeared?

Microsoft Teams pro macOSfake application installation (2026)

At the beginning of 2026, ClickFix also spread significantly among macOS users in Czechia and Slovakia. Attackers manipulated search results in the browser so that users looking for Microsoft Teams were redirected to a fraudulent website containing fake installation instructions. Instead of Teams, following those instructions caused them to download an infostealer designed to steal data. According to ESET, ClickFix accounted for three quarters of all detected malware attacks targeting macOS in Czechia and Slovakia in the first quarter of 2026.

4. Fake problems with documents and online services

What might you encouter?

A document that will not open, a microphone that suddenly stops working before a call, or a request to register in order to access a file. The attack exploits situations like these.

The user is given supposed instructions for fixing the problem. The more urgently they need to continue working, however, the easier it is to overlook that the suggested procedure is unusual.

Be careful!

A document or online service should
not require you to
run commands
or use system tools

simply to open it or make it work.

Be particularly cautious when the supposed
fix requires an
unusual procedure
outside
the application
or service itself.

Where has this variant appeared?

TA571 fake Microsoft Word and OneDrive documents (2024)

One of the first prominent examples was a campaign by the TA571 group in March 2024, which involved more than 100,000 messages and affected thousands of organizations worldwide. The HTML attachments imitated the Microsoft Word interface and displayed an error claiming that the required “Word Online” extension was missing. The user was then given an option to “fix” the problem, which ultimately resulted in the execution of a malicious command. Later campaigns used a similar scenario with attachments presented, for example, as invoices or financial documents.

What to do if you encounter ClickFix?

If you have not followed the instructions yet:

  • Stop and do not continue following the instructions. Do not open Run, PowerShell, or Terminal, and do not paste clipboard content into them simply because a website, document, or supposed verification asks you to do so.
  • Verify the situation through another channel. If a page reports an error, requests an update, or asks for verification, open the service separately or use its official application.
  • Report the suspicious website, email, or document to the MU Cybersecurity Team.

If you have already followed the instructions:

  • Check your device for malware by following our guide.
  • Report the suspicious website, email, or document to the MU Cybersecurity Team. In particular, describe what you did and where the instructions came from.
  • Keep the website, email, or document available and do not use the device for sensitive activities. Do not delete or attempt to fix anything, and until the incident has been resolved, do not use the device to sign in to important services.

Want to learn more about ClickFix?

      • HuntressClickFix Gets Creative: Malware Buried in Images
        Describes ClickFix campaigns using fake verification prompts and fake Windows updates, which then concealed parts of the malware directly inside image files.
      • ESETClickFix on macOS
        Covers the significant increase in ClickFix attacks targeting macOS users in Czechia and Slovakia, including fake websites imitating the installation of Microsoft Teams.
      • Push SecurityInstallFix
        Describes a newer variant that imitates installation pages for well-known tools and presents users with a malicious command disguised as a legitimate installation procedure.
      • ZscalerAI Generated ClickFix Attack Delivers SmartRAT
        Shows how generative AI tools were used to create fraudulent websites for a ClickFix campaign that impersonated a bank and distributed the remote-access malware SmartRAT.
      • Check PointFileFix
        Covers the related FileFix technique, in which the user pastes a command into the Windows File Explorer address bar instead of the Run dialog, under the pretext of opening a file.

You are running an old browser version. We recommend updating your browser to its latest version.

More info