Skip to content
LiveNext 12:05:09

Definition

What is ClickFix attack?

ClickFix attack is a ClickFix attack is a social engineering trick that gets you to copy, paste and run a malicious command yourself, usually from a fake error, CAPTCHA or install page.

A ClickFix attack is a scam that makes you the delivery mechanism. Instead of exploiting a flaw in your software, the attacker shows you a convincing page and talks you into running their command on your own machine.

How it works

  1. The lure. You reach a page through a phishing email, a malicious ad, a poisoned search result or a compromised website.
  2. The fake problem. The page shows a made-up error, a CAPTCHA, a "verify you are human" box or an install guide.
  3. The fake fix. It tells you to copy a command, open a terminal or the Windows Run dialog, paste it and press Enter. Many pages have a Copy button that quietly places a different command on your clipboard than the one displayed.
  4. The payload. The command downloads and runs malware, often a program that steals passwords and saved sessions, or one that gives the attacker remote access.

Why it works

Security software is built to stop programs from sneaking in. Here you start the program yourself, so many automated defenses never see an intrusion. The page also borrows trust: it looks like a brand you know, and the steps feel routine.

Developers are a particular target. Many real tools, including AI coding assistants, install with a single line pasted into a terminal, so pasting a command from a web page feels normal. Developers also tend to hold source code, cloud keys and access to production systems.

How to protect yourself

  • Type the address. Go to the vendor's site directly or use a bookmark. Skip sponsored search results for software downloads.
  • Read before you run. Paste the command into a plain text editor first, not the terminal, and check every address in it. A command that decodes hidden text before running it is a red flag.
  • Be suspicious of any page that tells you to open a terminal to prove you are human or fix a browser error. Real CAPTCHAs never do.
  • If you ran one, act fast. Disconnect the machine, tell your security team, and rotate the passwords, keys and tokens it held.

How it relates to other terms

ClickFix is a form of social engineering, close to phishing but ending in a command rather than a stolen login. It is different from prompt injection, where hidden text manipulates an AI model instead of a person, though the defensive habit is similar: treat instructions from untrusted content as data, not orders. AI tools do not cause ClickFix, but their popularity gives attackers fresh brand names to imitate.

A good rule is to treat "copy this and run it" from any page you did not choose to visit as a command from a stranger.

Questions people ask

What is a ClickFix attack?

A scam that tricks you into running a malicious command yourself, usually by showing a fake error, CAPTCHA or install page with a command to paste.

How do I avoid ClickFix attacks?

Type the vendor's address yourself, avoid sponsored results for downloads, and paste commands into a text editor to read them before running anything.

ClickFix attack in the news