iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A ClickFix attack tricks someone into copying or running attacker-supplied instructions, often from a fake browser warning or CAPTCHA. Instead of exploiting a software flaw, it uses the person as the bridge between a webpage and a trusted utility such as Windows Run or PowerShell. CrowdStrike describes layered controls that can disrupt the browser step, detect suspicious execution, identify follow-on identity abuse, correlate activity, and support response—but no single control guarantees prevention.
What is a ClickFix attack?
ClickFix is a social-engineering technique: a page or message invents a problem and tells the visitor to fix or verify something by running a command. The prompt may resemble a meeting error, browser verification, fake CAPTCHA, or system alert. CrowdStrike author Hananel Livneh described it as “a social engineering technique that turns the victim into the mechanism for executing an attack.”
The distinction matters: the user is persuaded to perform the action, rather than the attack depending solely on an automatic download or software vulnerability. The command can still use legitimate system tools, which may make the activity harder to distinguish from normal administration.
Free tools Windows power users keep installed
One-click scans. No signup required.
How the attack works
- A lure brings the person to the page. Common routes include phishing email, malicious advertising, and compromised or malicious websites. The page may imitate a familiar service or display a convincing error.
- The page supplies an instruction. A fake error, CAPTCHA, or system message tells the visitor to take a corrective action. Some pages use JavaScript to copy a command to the clipboard; Microsoft says campaign operators may obfuscate both the page-generating JavaScript and commands.
- The person runs it in a trusted utility. Instructions may direct the visitor to Windows Run, PowerShell, Terminal, or another operating-system tool, then paste and execute the command. The command may invoke PowerShell, VBScript, or another interpreter.
- The command retrieves or launches a payload. Depending on the campaign, it may download or execute additional code. Microsoft has documented payload categories including infostealers, remote-access trojans, loaders, and rootkits; some campaigns load payloads in memory through legitimate binaries.
- The intrusion can continue beyond the first command. Follow-on activity may include credential theft, persistence, command and control, data theft, malware deployment, or access to other systems.
CrowdStrike attributes a 563% increase in incidents involving fake CAPTCHA lures in 2025 to its 2026 Global Threat Report. That figure concerns fake-CAPTCHA incidents, not all ClickFix activity.
#1 Best Overall
What recent cases show
Fake video-conferencing site used in a 2026 campaign
CrowdStrike says that in July 2026, STARDUST CHOLLIMA very likely targeted an employee at a financial-services entity using infrastructure made to resemble a video-conferencing site. The employee almost certainly encountered a fake technical issue and command. CrowdStrike says execution triggered a PowerShell/VBScript chain that deployed two previously unknown malware families, GeniexLoader and GeniexRAT.
Fake CAPTCHA prompts targeting Ukrainian visitors
CrowdStrike says Falcon Complete MDR detected likely VOODOO BEAR intrusions in May and June 2026 affecting employees believed to be Ukrainian at organizations in France, the United States, and Canada. CrowdStrike assesses that the actor almost certainly used fake CAPTCHAs shown to Ukrainian visitors of compromised Ukrainian websites. The prompts led to PowerShell commands that downloaded a VBScript payload.
Rank #2
- PREMIUM-QUALITY RECORD BOOK FOR DEALERS & COLLECTORS: Clever Fox Firearms Record Book is designed to help professional firearm dealers keep detailed and legally compliant acquisition and disposition information.
- 129 PAGES WITH 1,342 NUMBERED ENTRIES TOTAL: There are 129 pages in this firearm log book with 1,342 numbered entries total. Each pre-printed entry allows you to record the firearm’s description, as well as receipt and disposition info.
- LARGE FORMAT & PLENTY OF SPACE FOR EVERY DETAIL: This firearm record book comes in large format and measures 10 by 7 inches, so you have lots of space to make detailed records and add all the information you need.
- STORAGE POCKET, DURABLE HARDCOVER & THICK NO-BLEED PAPER: This gun record book features a pocket for loose papers, a pen loop, an elastic band, and a bookmark. The hardcover is made of durable vegan leather. The pages are thick 120gsm paper.
- 60-DAY MONEY-BACK GUARANTEE: We will exchange or refund your book of firearms if you aren’t satisfied with your personal firearms record book for any reason. Reach out to us via message to refund your personal gun log book.
A 2025 Lampion example, with an important limit
Microsoft’s 2025 case study describes a phishing ZIP/HTML route to a fake Portuguese tax-authority site, followed by PowerShell and staged VBScript activity. In the investigated sample, however, the final Lampion malware was not delivered: the download command was commented out. The case illustrates the delivery chain, not a confirmed successful Lampion infection from that sample.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsHow CrowdStrike maps defenses to the attack chain
CrowdStrike describes a defense-in-depth approach: controls at different points can create opportunities to prevent, detect, correlate, or respond to activity. The following are vendor-described capabilities, not a guarantee that every ClickFix attempt will be stopped. The exact product packaging and availability are not established here; named modules should not be assumed to be included in every deployment.
Rank #3
| Attack stage | CrowdStrike offering described | Role CrowdStrike describes |
|---|---|---|
| Browser lure and copy/paste | Seraphic Enterprise Browser | Provides visibility and enforcement in the browser; CrowdStrike says it can disrupt malicious web behavior and the copy-and-paste mechanism. |
| Command or payload execution | Falcon Prevent and Falcon Insight XDR | Can identify and prevent suspicious PowerShell, VBScript, process, command-line, and related behavioral activity. |
| Credential abuse and lateral movement | Falcon Identity Threat Protection | Can help detect and stop credential abuse and lateral movement after credentials are compromised. |
| Activity spanning domains | Falcon Next-Gen SIEM | Can correlate endpoint, identity, browser, cloud, and other telemetry. |
| Hunting, investigation, and response | Falcon Adversary OverWatch and Falcon Complete | CrowdStrike describes continuous threat hunting, investigation, containment, and remediation. |
These layers address different failure points. Browser controls may disrupt the delivery or clipboard step; endpoint controls may identify suspicious execution; identity signals can reveal abuse after credentials are exposed; and correlation and response can help investigators connect and contain activity. Their effectiveness depends on what is deployed, configured, and visible in a particular environment.
Why ClickFix can affect macOS as well as Windows
ClickFix is not limited to Windows. CrowdStrike and Microsoft document macOS activity, because the underlying tactic—persuading a user to run supplied instructions—can be adapted to different operating systems and utilities. CrowdStrike’s macOS hunting examples include shell, curl, xattr, and chmod activity. A defense that watches only Windows Run or PowerShell would therefore miss the broader pattern.
What users and administrators can do
If a page asks you to run a command
- Do not paste or run commands supplied by an unsolicited webpage, CAPTCHA, pop-up, or support prompt.
- Verify the claimed problem through a known, independently reached service or support channel—not through contact details or links on the suspicious page.
- If the prompt appeared during work, report it to your organization’s security team and preserve the page or message details if safe to do so.
For organizations
- Teach users that a webpage asking them to open Run, PowerShell, Terminal, or another command utility is a warning sign, even when framed as verification or troubleshooting.
- Harden device configurations. Microsoft gives disabling the Run dialog as an example where users do not need it for daily tasks; apply restrictions in a way that fits legitimate workflows.
- Use browser, endpoint, identity, and centralized monitoring controls together where available, so detection does not rely on blocking the initial page alone.
Microsoft notes that the user-interaction element may bypass conventional and automated controls, which is why user education and device hardening complement technical detections. The U.S. Department of Health and Human Services also described users being induced to copy and execute code from fake browser alerts in its 2024 sector alert.
Quick Recap
Sources
- CrowdStrike, “Copy, Paste, Compromised: How ClickFix Attacks Work and How CrowdStrike Stops Them,” September 29, 2026
- Microsoft Security Blog, “Think before you Click(Fix): Analyzing the ClickFix social engineering technique,” August 21, 2025
- U.S. Department of Health and Human Services, “ClickFix Attacks Sector Alert (TLP:CLEAR),” October 29, 2024
- CrowdStrike, “Enhanced Network Visibility: Falcon macOS Sensor Updates,” 2026
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

