
By The NetSys Group Team
ClickFix is a social-engineering trick that gets people to infect their own computers. A fake error message or "verify you're human" box tells you to press a couple of keys and paste something to fix the problem. What you paste is actually a command that quietly installs malware. Because you run it yourself, there is no attachment to block and no file for antivirus to catch.
It spread fast. ClickFix attacks jumped more than 500% in the first half of 2025 and became the second most common attack method behind ordinary phishing, according to ESET's H1 2025 Threat Report. For a small business the problem is simple: your email filter and your antivirus were built to stop files and links, and this attack uses neither.
What is a ClickFix attack?
ClickFix is a technique where a fake CAPTCHA, "verification" step, or error message tells you to open a Windows dialog and paste text to prove you are human or fix an issue. The pasted text is a hidden command that downloads and runs malware. You execute it yourself, so no file is ever scanned or flagged.
The lure is the whole trick. It looks like a routine hoop you jump through every day online: "Press Windows + R, then Ctrl + V, then Enter." Follow those steps and you have just launched a command you never saw. On a Mac the wording changes to a Terminal command, but the idea is identical.
Why does ClickFix slip past antivirus and email filters?
Traditional defenses look for something bad arriving: a malicious attachment, a flagged download, a known-bad link. ClickFix hands the victim a set of instructions instead. The dangerous part is a command typed into tools that Windows ships with and trusts, usually the Run box and PowerShell. Security teams call this "living off the land," because the attacker borrows software that is already on the machine.
Nothing about that looks unusual to a signature-based scanner. PowerShell runs a thousand legitimate tasks a day. By the time the command reaches out to the internet and pulls down the real payload, the person has already granted it permission by hitting Enter.
Where do these fake CAPTCHAs show up?
All over the places your staff already go. Attackers plant the fake prompts on hacked but otherwise normal websites, buy search and social ads that lead to them, and send links in phishing emails and fake meeting invites. In one campaign documented in 2026, hundreds of education and technology websites were hijacked to serve ClickFix pages to ordinary visitors.
It is part of a broader shift toward attacks that skip the inbox entirely, the same pattern behind QR code phishing and callback phishing. The common thread: get a human to take an action your filters never see.
What happens after someone pastes the command?
Usually the first payload is an infostealer. Within seconds it can grab saved browser passwords, autofill data, and active session cookies. Those stolen cookies are especially damaging because they let an attacker log into email and cloud apps as your employee without a password and often without triggering multi-factor authentication. We wrote about that exact move in session hijacking.
From there it can get worse. Access brokers sell that foothold, and ransomware crews buy it. What started as one distracted click can turn into locked files and a stolen mailbox. This is the point where managed detection and response earns its cost, by catching the behavior after the click rather than relying on the click never happening.
How do you protect a small business from ClickFix?
You cannot filter your way out of this one, so the defense is a mix of people and configuration.
- Teach one rule. No legitimate website, CAPTCHA, or IT department will ever ask you to paste text into the Windows Run box or PowerShell. If a page gives those instructions, close it and report it. That single rule stops most of these attacks cold.
- Lock down the tools it abuses. Most staff never need the Run dialog or PowerShell. Restricting them for standard users, along with application control, removes the runway the attack needs.
- Run EDR or MDR, not just antivirus. Behavior-based tools flag a browser spawning PowerShell that reaches out to the internet, which is exactly what ClickFix does.
- Remove local admin rights. Least privilege limits how far a payload can spread from the first machine.
- Have an incident response plan. If someone does run it, minutes matter. A rehearsed incident response plan beats improvising.
Pairing that with regular security awareness training and hardened endpoints is the core of what our cybersecurity services put in place for clients.
Frequently asked questions
Is ClickFix a virus?
Not exactly. ClickFix is the delivery method, a social-engineering trick that convinces you to run a command. That command is what installs the actual malware, which is often an infostealer or a loader that pulls down ransomware. The technique is the con; the virus is what it drops.
How can I tell a CAPTCHA or error message is fake?
The tell is the instructions. Real CAPTCHAs ask you to click a box or pick images. If a page tells you to press Windows + R, open PowerShell or Terminal, or paste something to continue, it is a scam. No genuine verification ever needs you to run a command on your own computer.
Does antivirus stop ClickFix?
Often not on its own. Because the victim runs a trusted built-in tool and no file is downloaded at first, signature-based antivirus can miss it. Behavior-based endpoint detection and response, tighter user permissions, and staff who know the one rule are far more reliable defenses.
An employee pasted the command. What now?
Treat it as a live incident. Disconnect the device from the network, do not shut it down yet if your response team wants to preserve evidence, and reset the user's passwords and sign them out of all sessions from a clean device. Then have IT or your security provider investigate what ran. Speed limits the damage.
Can MFA protect us from ClickFix?
Multi-factor authentication still matters, but ClickFix payloads can steal active session cookies that bypass it. Phishing-resistant methods like passkeys and hardware keys hold up far better, and pairing MFA with fast detection closes the gap when a token is stolen.
If you are not sure whether your current setup would catch an attack like this, we can check. The NetSys Group offers a complimentary security risk assessment that looks at exactly these gaps for your business.
By The NetSys Group Team. The NetSys Group has delivered managed IT, cybersecurity, and cloud services since 1998. Our engineers hold degrees in electrical and computer engineering and are certified Microsoft and Cisco instructors, serving businesses across NY, NJ, CT, PA, and Southwest Florida.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



