Skip to content
Tech News
← Back to articles

ClickFix attacks infecting PCs and Macs are going viral

read original get Malwarebytes Premium Security → more articles
Why This Matters

ClickFix has gone from a niche trick to one of the most widely used infection methods, working across Windows and macOS because it relies on social engineering rather than software exploits. Attackers compromise legitimate, trusted websites and show fake Cloudflare-style CAPTCHAs that instruct users to paste a command into Run, PowerShell, or Terminal. Its spread — including by state-backed groups — shows how years of hostile, friction-filled web UX have trained casual users to comply with absurd instructions.

Key Takeaways
Worth a Look

Malwarebytes Premium Security — ClickFix scams trick people into pasting malicious commands, so a second layer of real-time protection is worth having on both PCs and Macs. Malwarebytes Premium runs alongside your system defenses and can flag and remove malware payloads that sneak in through compromised websites. It's an easy safety net for family members who aren't scrutinizing every fake CAPTCHA prompt.

See Malwarebytes Premium Security on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

It wasn’t that long ago that ClickFix attacks were exotic. Now the technique has become mainstream as attackers reap its simplicity and effectiveness in infecting users of PCs and Macs alike. All that’s required is a compromised website—a painless enough task—a fake CAPTCHA overlay, and the inclusion of a single terminal command. So many visitors get suckered into pasting and running the command that just about every malware pusher has adopted the technique. Even Kremlin-backed hacking groups are joining in.

“Reddit is becoming post after post after post of people getting their computer infected via ClickFix,” independent researcher Kevin Beaumont observed Thursday. “Legit websites everywhere [are] getting hacked to serve the fake captcha prompts.”

How many of us make things worse

More seasoned Internet users—a fair number who read this site—are quick to dismiss the attack. They typically blame the people who fall for the scams and marvel at their gullibility and lack of attention. The reality is that for more casual users, using computers and the Internet has become so difficult—think impossible-to-close interstitials, CAPTHAs with an endless series of pictures to analyze, and constantly changing interfaces that bury the features they’re looking for—that they have grown desensitized to instructions that seem ridiculous and burdensome.

ClickFix attackers are capitalizing on this fatigue. Typically, attacks begin with a simple CAPTCHA image, often masquerading as one from Cloudflare. After engaging with the box, the user sees a line of text, often obscured in a way to mask any malicious commands. Then the user is instructed to copy the text and paste it into the Windows Run, PowerShell, or macOS terminal and click Enter.

The instructions come from websites people have used for years. The directions seem no more suspicious than things they’ve been required to do for a decade. Why would someone without a firm grasp of computer security have any reason to hesitate?