Blog

Security Alert: ClickFix Attack Campaigns Targeting Business Users

A growing cyber threat known as “ClickFix” is being used to trick users into infecting their own computers. Unlike traditional phishing attacks that rely on clicking a malicious link or opening an attachment, ClickFix attacks convince users to manually execute malicious commands on their device. Microsoft has reported that these attacks are now targeting thousands of organizations globally each day and are frequently used to deploy password stealers, remote access tools, and other malware.

How the Attack Works

The attacker presents a convincing error message, document access warning, browser problem, or CAPTCHA verification screen. The instructions appear to be a legitimate “fix” for the issue.

The victim is then instructed to:

  • Press Windows + R
  • Open PowerShell, Terminal, or Command Prompt
  • Paste a command that has been secretly copied to the clipboard
  • Press Enter to “complete verification” or “repair the issue”

Following these instructions launches malicious code directly on the computer, bypassing many traditional security controls because the user initiated the action themselves.

Common ClickFix Lures

Attackers frequently disguise the attack as:

  • CAPTCHA or “Verify You Are Human” screens
  • Document viewing errors
  • Browser update notifications
  • Microsoft Office errors
  • Security verification requests
  • Cloudflare or Google verification pages
  • Website access troubleshooting instructions

These prompts often appear highly legitimate and may closely resemble well-known services.

Red Flags

🚩 A website asks you to open Windows Run, PowerShell, or Command Prompt

🚩 A CAPTCHA instructs you to paste text into a Windows tool

🚩 You are told to press Windows + R as part of a verification process

🚩 A website claims a document cannot be viewed until you run a command

🚩 Instructions include copying and pasting text you do not understand

Legitimate websites, Microsoft services, insurance carriers, and CAPTCHAs do NOT require users to run commands on their computer to verify their identity or view documents.

Impact

Successful ClickFix attacks have been observed delivering:

  • Password-stealing malware
  • Browser cookie theft
  • Session token theft
  • Remote access trojans (RATs)
  • Information-stealing malware
  • Data exfiltration tools

Compromised credentials can lead to email account takeovers, business email compromise, fraudulent wire requests, and unauthorized access to company systems.

What To Do

Close the browser tab immediately if you encounter these instructions.

Contact Computer Rescue if a website asks you to run commands or paste content into Windows tools.

Report suspicious emails, websites, or pop-ups immediately.

If you already followed the instructions, disconnect from the network and contact IT/security without delay.

Remember

If a website asks you to open PowerShell, Command Prompt, Terminal, or the Windows Run box, STOP.

A legitimate CAPTCHA checks a box. A malicious CAPTCHA asks you to run commands.

When in doubt, call Computer Rescue before proceeding.


Computer Rescue Security Advisory

Our team is actively monitoring ClickFix-related threats and recommends immediate reporting of any suspicious verification screens, document access errors, or requests to execute commands on a workstation. Early reporting can significantly reduce the impact of credential theft and malware infections.