Breaking
Cyber CrimeDeveloping Story

ClickFix Goes Mainstream, Hits PCs and Macs

ClickFix attacks have spread from exotic to mainstream, infecting Windows and macOS users via fake CAPTCHAs and terminal commands.

··1 hour ago·4 min read
padlock on laptop with light trails
Photo by FlyD on Unsplash

What began as an exotic attack technique is now a mainstream infection vector, according to a report from Ars Technica. ClickFix attacks are compromising PCs and Macs alike, driven by their simplicity and effectiveness. Attackers need only a compromised website, a fake CAPTCHA overlay, and a single terminal command to trick visitors into running malware.

The scale of the problem is evident from online discussions. "Reddit is becoming post after post after post of people getting their computer infected via ClickFix," independent researcher Kevin Beaumont observed Thursday. "Legit websites everywhere [are] getting hacked to serve the fake captcha prompts."

From Niche Tactic to Widespread Threat

Not long ago, ClickFix was considered an unusual approach. Today, it has been adopted by a wide range of malware operators, including Kremlin-backed hacking groups. The technique's success has made it a staple in the cybercrime ecosystem, with attackers constantly refining their methods.

The attack flow is straightforward: a user visits a compromised website, encounters a fake CAPTCHA prompt, and is instructed to copy a line of text and paste it into their system's run dialog or terminal. The command then executes malicious code. This process bypasses many traditional security measures because it relies on the user's own actions.

The Mechanics of a ClickFix Infection

ClickFix attacks typically start with a CAPTCHA image that mimics legitimate services like Cloudflare. After interacting with the box, the user sees a line of text, often obscured to hide malicious commands. They are then told to copy the text and paste it into Windows Run, PowerShell, or the macOS terminal, and press Enter.

These instructions come from websites that people have used for years, making them seem no more suspicious than routine tasks. For users without a firm grasp of computer security, there is little reason to hesitate. The attackers capitalize on this familiarity and the fatigue caused by endless CAPTCHAs and confusing interfaces.

Why Users Fall for the Scam

More seasoned internet users often dismiss the attack, blaming victims for their gullibility. However, the reality is that using computers and the internet has become increasingly difficult for casual users. Impossible-to-close interstitials, CAPTCHAs with endless picture grids, and constantly changing interfaces have desensitized people to burdensome instructions.

ClickFix attackers exploit this fatigue. The directions seem no more suspicious than things users have been required to do for a decade. For someone without a strong security background, there is little reason to question the prompt.

"The pivot to ClickFix in late May 2026 eliminates the code-signing requirement entirely, substituting the legitimacy of a validly signed installer with a different form of legitimacy: a user voluntarily executing the malicious command in their own terminal."

— BlueVoyant, security firm

According to BlueVoyant, the shift to ClickFix has made attacks more efficient. Previously, malware like Lorem Ipsum required resource-intensive infrastructure, including SEO-manipulated download portals, Microsoft-trusted signing certificates, and rotating domains. Now, attackers can bypass code-signing entirely by convincing users to run commands themselves. This broadens the victim pool from those searching for specific software to anyone browsing a compromised site.

macOS Users Are Not Immune

The situation for macOS users is equally concerning. Mac security firm Jamf and an independent researcher have documented macOS variations of ClickFix that can bypass Gatekeeper protections. These attacks demonstrate that no platform is safe from the technique.

Attackers continue to find new ways to abuse public services. Cisco Talos reported that some campaigns use publicly published Google Sheets documents to host malicious commands. Other groups, including Russia's state-sponsored Sandworm, have hosted control infrastructure in blockchain-based smart contracts. Security firm Netskope recently found a campaign using this approach, with 5,400 sites beaconing to it, indicating the reach and scope of the operation.

The Cat-and-Mouse Game Continues

As OS makers and defenders build new defenses, attackers keep finding documented ways to work around them. The adoption of ClickFix by a diverse set of threat actors, from cybercriminals to state-sponsored groups, underscores its effectiveness.

The technique's simplicity and high success rate mean it is unlikely to disappear. Victim-blaming or shaming only makes the problem worse, as it discourages reporting and open discussion.

Defenses and Mitigations

There are several tools designed to blunt ClickFix attacks. For macOS, BlockBlock monitors for processes that seek to permanently install themselves and can block attacks as soon as a user presses the ⌘+V keys. Ublock has been updated to provide similar protection.

Beyond technical fixes, those with security training should build awareness among less experienced neighbors, family members, and friends. The mass adoption of ClickFix demonstrates its success, and it is not going away any time soon.

What This Means for You

The mainstreaming of ClickFix suggests that users can no longer assume a prompt is safe just because it appears on a familiar website. The attack's reliance on social engineering means that technical defenses alone may not be enough. This could mean that organizations need to double down on user education, emphasizing that legitimate services rarely ask users to paste commands into a terminal.

For individuals, the takeaway is to treat any instruction to run a terminal command with extreme caution, even if it comes from a site you trust. As ClickFix continues to evolve, staying informed and skeptical may be the best defense.

#clickfix#malware#social engineering#macos#windows

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories