If you have spent any time on the internet lately, you have seen a CAPTCHA. The little box that says "I'm not a robot." Maybe some blurry traffic lights to click on. You know the drill.
Attackers know it too. And now they are using your familiarity with that process to put malware on your computer without ever exploiting a single piece of software.
The attack is called ClickFix. It is one of the fastest-growing threats in cybersecurity right now, and it is targeting regular users at companies just like yours.
What ClickFix Is and How It Works
ClickFix is a widespread campaign that uses fraudulent CAPTCHA pages to socially engineer victims into executing malicious scripts themselves.
Here is the basic sequence:
- You land on a compromised website. It could be a page you reached through a phishing email, an ad, or even a legitimate site that was hacked without the owner knowing.
- A pop-up appears that looks like a standard Cloudflare or Google verification prompt.
- Instead of just clicking a box, the page instructs you to press Windows Key + R, then Ctrl + V, then Enter.
- You follow the steps because they look like a routine system action.
- Your computer is now infected.
The reason those three keystrokes work is straightforward. Malicious JavaScript embedded in the site loads a fake CAPTCHA page that closely mimics Cloudflare's verification interface. A malicious PowerShell command is already placed on the clipboard and executes when pasted into the Run dialog, giving the attacker code execution without triggering browser download prompts or security warnings.
You did not click a suspicious link. You did not open a strange attachment. You ran the attack yourself because the page told you it was just a verification step.
What Happens After You Run It
StealC, one common payload delivered this way, exfiltrates browser credentials, cryptocurrency wallets, Outlook credentials, system information, and screenshots to an attacker-controlled server.
Other campaigns deliver different payloads. Attackers can deploy tools such as LummaStealer, a highly evasive infostealer designed to harvest credentials, financial information, and other sensitive data at scale.
In more serious incidents, the payload is a remote access trojan. That gives the attacker persistent access to the machine, not just a one-time data grab. From there they can move laterally through your network, deploy ransomware, or sell access to other criminal groups.
Stealers, remote access trojans, and loaders appear within minutes of execution, often before anyone suspects something is wrong, leaving little time for containment.
The Numbers Are Not Reassuring
This is not a niche threat. The scale of ClickFix adoption by attackers has been dramatic.
H1 2025 (ESET)
per Microsoft 2025
by Microsoft Defender
- ClickFix attacks surged 517% in the first half of 2025, becoming the second most common attack vector behind only phishing and accounting for nearly 8% of all blocked attacks in that period.
- Microsoft's 2025 Digital Defense Report named ClickFix the number one initial access method, responsible for 47% of all attacks observed by Microsoft Defender Experts, surpassing traditional phishing at 35%.
- Between May 2024 and May 2025, the volume of phishing URLs tied to ClickFix nearly quadrupled.
- In early 2025, Microsoft observed thousands of devices being affected per month, even with endpoint detection and response solutions enabled.
That last point matters. This attack is slipping past tools that were supposed to catch it.
Why Security Tools Often Miss It
Traditional security is built to catch unauthorized activity. ClickFix generates authorized activity.
Email gateways are not involved and malware scanners may have nothing to inspect. Endpoint tools can record the event, but the command itself is executed by the user through a trusted shell.
When the victim pastes the command, the system treats it as a normal action. Many endpoint detection and response tools interpret it the same way.
The attack is also designed to evade blocklists. ClickFix campaigns often contain only a clean URL that redirects through traffic distribution systems before landing on the attack page. Browser protections like Google Safe Browsing do not trigger because the browser is not downloading an executable. The user is.
Real Organizations Are Getting Hit
This is not just an individual user problem.
The website of iClicker, a popular student engagement platform used by approximately 5,000 instructors and 7 million students, was compromised with a ClickFix attack between April 12 and April 16, 2025. Visitors who clicked the "I'm not a robot" button had a PowerShell script silently copied to their Windows clipboard, then were instructed to run it.
More than 100 automotive industry websites were infected via a streaming service provider in an attack reported in March 2025 targeting car dealerships. Healthcare has been targeted as well, with malicious code injected into a physical therapy video site that redirected users to ClickFix prompts.
According to the U.S. Department of Health and Human Services, ClickFix has extensive reach and has appeared in many services used by the general public.
What ClickFix Looks Like in 2026
The technique is still evolving. Attackers are not standing still.
In January 2026, a new ClickFix variant called CrashFix was identified, delivered through a malicious Chrome extension that impersonated a legitimate ad blocker. The attack deliberately crashed the victim's browser, then prompted them to follow recovery steps that executed the malicious command.
Recent campaigns have targeted social media content creators by claiming they are eligible for free verified badges, instructing them to copy authentication tokens from their browser cookies into a fake form. One campaign used 115 web pages across its attack chain and eight separate data exfiltration endpoints.
Malvertising is another common delivery path. In one campaign, users who pressed play on a free movie streaming site had a ClickFix landing page open in a new tab, funneling tens of thousands of unique visitors to scam pages in a single day.
The One Rule That Stops This Attack
No real CAPTCHA, no real verification system, and no real browser check will ever ask you to open PowerShell or the Windows Run dialog, paste text into it, and press Enter.
Full stop. If a website asks you to do that, close the tab.
Not sure if your clipboard was hijacked? Open Notepad and press Ctrl + V. If it contains a command with words like "powershell," "cmd," "IEX," or a URL you do not recognize, that page was attempting to infect you. Close your browser and contact your IT provider immediately.
What Businesses in the Dayton Area Should Do
User awareness is the first line of defense here, but it cannot be the only one.
- Train your staff on this specific attack. General phishing awareness is not enough. Your employees need to know that no legitimate website will ask them to run commands on their own computer. Show them what the prompt looks like. Make it concrete.
- Restrict PowerShell for standard users. Most employees do not need to run PowerShell scripts as part of their normal work. Locking down access to it is one of the most effective technical controls available.
- Use endpoint protection with behavioral detection. Standard antivirus is not enough. You need a solution that monitors for unusual process behavior, not just known malware signatures. Bitdefender GravityZone with EDR is what we deploy for managed clients at Dayton Allied Business Solutions for exactly this reason.
- Keep software and browsers updated. Attackers target outdated environments. Patch management removes the low-hanging fruit.
- Have a plan for when something gets through. Know who to call. Know what steps come first. Incident response without a plan costs you more time and more money than having one.
The Bottom Line
ClickFix works because it exploits trust in everyday computer interactions. It does not need a vulnerability in your software. It needs a user who follows instructions.
ClickFix campaigns impersonate infrastructure: browsers, operating systems, update mechanisms, verification flows, and error states. Social engineering training often focuses on teaching users to question unexpected emails. Users are far less likely to question instructions that appear to come from the system itself.
That is exactly what makes this one dangerous.
Is your business protected?
We can assess your current security posture and help you put the right controls in place.
