Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →ClickFix is a social-engineering attack that makes running a malicious command look like a routine fix, CAPTCHA check, or support instruction. A page may ask you to copy text and paste it into Windows Run or a terminal. The copied command—not the apparent verification task—is the danger: it can use built-in system tools to download or launch malware.
How does ClickFix work?
- You encounter a deceptive prompt. You might reach it through phishing, a malicious ad, a compromised website, or a redirect. The page imitates a familiar task and may claim you need to verify that you are human, fix a browser or document error, install an update, or follow support instructions. Microsoft describes these routes and lures; HHS HC3 documented fake browser-update campaigns.
- The page asks you to copy and run text. A button may place a command on your clipboard, then direct you to paste it into Windows Run, Windows Terminal, or another shell. Because the instruction appears to be part of verification or troubleshooting, the action can seem ordinary. It is not. Microsoft and CIS describe this copy-and-paste approach.
- The command starts an execution chain. Depending on the campaign, it can call system utilities or scripts to fetch or launch a payload. Microsoft’s 2025 reporting describes execution paths involving PowerShell and mshta.exe, but there is no single command used by every ClickFix campaign. Microsoft’s campaign analysis provides examples.
- The payload pursues the campaign’s objective. Observed outcomes include information theft, remote access, and malware staging; some campaigns have involved ransomware. A ClickFix attempt does not necessarily succeed, and the name does not identify one particular payload or guarantee a specific outcome. Microsoft, CIS, and HHS HC3 describe different campaigns and risks.
What makes a ClickFix prompt suspicious?
The defining warning sign is a webpage, pop-up, email, or message asking you to copy and run a command. A genuine-looking CAPTCHA or familiar logo does not make that instruction safe. Treat commands supplied by an untrusted page as high risk; verify the claimed problem through a separate, trusted route instead of following the page’s directions. ClickFix works by disguising command execution as routine troubleshooting or verification.
Common lures and delivery routes
| What varies | Examples |
|---|---|
| Delivery route | Phishing, a malicious advertisement, a compromised website, or a redirect. |
| Pretext | Fake CAPTCHA or browser verification, an update, a document or page error, a job-related task, or support instructions. |
| Execution environment | Windows Run, Windows Terminal, or another command shell. |
| Payload objective | Information theft, remote access, malware staging, or—in some observed campaigns—ransomware. |
These are campaign variations, not steps every attack follows in exactly the same way. For example, Google Threat Intelligence has described a ClickFix campaign targeting macOS users with Atomic Stealer, while Microsoft and HHS have documented Windows-focused examples. The prompt and commands depend on the campaign and the operating system it targets.
How common is ClickFix?
Published figures show substantial activity in specific security datasets, but they are not estimates of ClickFix’s share of all cyberattacks:
#1 Best Overall
- Microsoft’s Digital Defense Report 2025 says ClickFix accounted for 47% of attacks in Defender Experts notifications in the last year covered by that report. That figure describes Microsoft’s notification telemetry, not all attacks worldwide.
- CIS’s Cyber Threat Intelligence team says ClickFix comprised more than one third of non-malware Albert Network Monitoring and Management alerts in the first half of 2025. That is a specific monitoring and alert context, not a population-wide rate.
- In an August 2025 blog, Microsoft reported campaigns targeting thousands of enterprise and end-user devices globally every day at the time of publication. This is Microsoft’s observation then, not a current census. Read Microsoft’s report.
How can users and organizations reduce the risk?
For individual users
- Do not paste or run a command because a webpage or message tells you to. Close the prompt and check the claimed issue through a trusted source, such as the service’s official app or support channel.
- Do not assume a familiar brand, CAPTCHA, or urgent error makes the instruction legitimate.
- If you already ran an unexpected command on a work device, contact your organization’s IT or security team promptly. Until you receive trusted guidance, avoid entering credentials or approving further prompts on that device.
For organizations
Microsoft recommends layered defenses rather than relying on a single control. Its Digital Defense Report 2025 recommends teaching users that pasting commands from unknown sources is as risky as clicking suspicious links. It also recommends technical controls and monitoring, including:
- Enable PowerShell logging and use Constrained Language Mode where appropriate.
- Watch for unusual clipboard activity followed by shell launches, and correlate clipboard events with downstream execution patterns.
- Harden browsers, including disabling clipboard access and scripting in untrusted browser zones where appropriate.
These controls can make campaigns harder to execute or detect suspicious behavior; they are not a guarantee that every attempt will be prevented.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

