Skip to content
Tech News
← Back to articles

ClickFix-based attacks are becoming widespread on both PC and Mac

read original more articles
Why This Matters

The rise of ClickFix-based attacks signifies a growing threat in social engineering that can easily deceive users on both PC and Mac platforms. This technique's effectiveness in spreading malware without traditional infrastructure makes it a significant concern for cybersecurity. Awareness and proactive security measures are crucial to mitigate these evolving threats.

Key Takeaways

Facepalm: Security researchers are highlighting the increasing prevalence of ClickFix-based threats. The social engineering technique is now being adopted in both simple and complex malicious campaigns. Worse yet, users are not paying enough attention to what strangers on the Internet are asking them to do.

Typical ClickFix social engineering attacks begin with a pop-up displayed over a trusted web page that provides some pressing instructions. Cybercriminals have weaponized CAPTCHA overlay windows to make the social engineering attempt more effective, asking users to copy, paste and execute a covert command from the Windows or Mac command line.

According to security researcher Kevin Beaumont, ClickFix victims are flooding Reddit with requests for help. Cybercriminals are now compromising legitimate websites to build new ClickFix-based attacks, allowing them to more easily trick unsuspecting users into executing malicious commands from web pages they regularly visit.

Beaumont thinks that business organizations working in the Windows ecosystem can neutralize ClickFix and other prompt-based threats by disabling the Start/Run prompt functionality altogether. Microsoft provides specific group policies to prevent certain user groups from accessing the prompt feature, although a majority of companies are unlikely to require such an extreme security measure.

ClickFix threats are well-suited for spreading malware, as the social engineering technique removes the need to build a "real" network infrastructure to deliver malware to target machines. There is no need to compromise pre-existing systems, use Microsoft-trusted certificates, or rotate malicious command-and-control domains to deliver the malware package.

The technique is so effective that Russia's state-sponsored actors and other APT groups have already integrated ClickFix into their complex modus operandi. Fake CAPTCHA windows can now be found inside publicly available Google Sheets documents or even in blockchain-based smart contracts.

Software vendors are trying to push back by developing new countermeasures for both the Windows and Mac ecosystems. However, malware developers have joined the arms race by researching new attack methods that continue to work. The ClickFix-based security epidemic is not going away anytime soon, the researchers warn. The growing number of users seeking simpler approaches to computing is making the cybercriminals' job much easier than it should be.