ClickFix malware turns one of the internet’s most familiar security checks into a trap. Instead of simply asking you to prove that you are human, a fake CAPTCHA may instruct you to open Windows Run, PowerShell, Windows Terminal, or the macOS Terminal and paste a command.
If you follow those instructions, you may actually install the malware yourself.
That distinction makes ClickFix dangerous. The attacker does not always need to exploit a technical vulnerability. Instead, the attack convinces a legitimate user to authorize the next step.
Recent campaigns show that this tactic is becoming more sophisticated. On August 7, 2026, Switzerland’s National Cyber Security Centre warned that more than 100,000 websites worldwide had been affected by compromised sites displaying fake CAPTCHA prompts. The agency was tracking seven active ClickFix campaigns at the time.
Then, on August 28, Microsoft documented an advanced ClickFix variant called TerminalFix that went far beyond installing a simple information stealer. The campaign could create persistent access to an organization’s internal network.
For employees and small-business owners, the lesson is simple:
A CAPTCHA should never require you to open a command line and paste instructions into your computer.

What Is ClickFix Malware?
ClickFix is primarily a social-engineering technique.
The attacker creates a convincing message that appears to solve a simple problem. Common examples include:
- “Verify you are human.”
- “Complete this CAPTCHA.”
- “Your browser needs an update.”
- “Something went wrong.”
- “Fix this DNS error.”
- “Open Terminal to continue.”
- “Press Windows + R to verify.”
The page may look professional. It may copy the appearance of Cloudflare, a software-download site, or another legitimate company.
However, the instructions are designed to make the victim execute a malicious computer command.
The Swiss NCSC reported that current fake CAPTCHA pages can even detect the visitor’s operating system. Windows users receive Windows-specific instructions, while Mac users receive commands designed for macOS.
This is not a Windows-only problem.
How Does a ClickFix Attack Work?
A typical ClickFix attack follows a simple pattern.
First, the employee visits a compromised or malicious website.
Next, a familiar verification screen appears.
The user may see a checkbox such as:
“Verify you are human.”
After clicking it, the website may silently place a malicious command into the computer’s clipboard.
The employee is then instructed to:
- Press Windows + R or open Windows Terminal or PowerShell.
- Press Ctrl + V to paste the command.
- Press Enter.
On a Mac, the victim may instead be told to open Terminal, paste a command, and run it.
The employee believes they are completing a verification step.
In reality, they may have just instructed the computer to download malware.
That is the core ClickFix trick.
Why Does ClickFix Work So Well?
ClickFix takes advantage of habits instead of technical weaknesses.
People are accustomed to CAPTCHAs.
We click boxes identifying ourselves as human. We select traffic lights and wait for verification screens. Therefore, another verification request may not immediately feel suspicious.
ClickFix adds one more psychological advantage.
The employee performs the action themselves.
Traditional malware may depend on a dangerous attachment or executable file. ClickFix can instead convince the victim to use legitimate tools already installed on the computer.
That can include:
- PowerShell
- Windows Terminal
- Windows Run
- curl
- macOS Terminal
Security professionals sometimes call this type of behavior living off the land because attackers abuse legitimate operating-system tools rather than relying entirely on obvious malicious programs.
Microsoft describes ClickFix as a technique that manipulates users into voluntarily beginning the infection process.
ClickFix Is Becoming More Dangerous
Early ClickFix campaigns frequently delivered information-stealing malware.
That alone is serious.
Infostealers can attempt to collect:
- Login credentials
- Browser data
- Authentication tokens
- Cryptocurrency wallet information
- Credit card information
- Sensitive documents
Microsoft reported in July 2026 that recent ClickFix campaigns delivering ACR Stealer could expose browser credentials, session tokens, authentication artifacts, and sensitive enterprise information.
However, recent attacks demonstrate that ClickFix can become the first step in something larger.
The TerminalFix Development
On August 28, 2026, Microsoft disclosed a ClickFix variant called TerminalFix targeting organizations across multiple industries.
Victims encountered a fake Cloudflare verification screen on a compromised website.
Instead of being directed to the traditional Windows Run box, users were instructed to open PowerShell or Windows Terminal and paste the supposed verification command.
Once executed, the attack could establish persistence, inspect Active Directory, identify servers, and eventually create a reverse tunnel into the victim’s network.
That changes the potential impact.
One employee following one fake CAPTCHA could give an attacker a foothold that may expose other systems on the business network.
Microsoft recommends that organizations finding evidence of this campaign treat the compromised computer as a possible network pivot point and investigate for credential exposure and lateral movement.
Mac Users Are Being Targeted Too
The old assumption that these attacks primarily target Windows users is increasingly unreliable.
Microsoft documented a macOS ClickFix campaign in August 2026 that became sophisticated enough to identify likely real Mac users before showing the malicious lure.
The attackers used browser fingerprinting to reduce the chances that automated security systems and researchers would see the same malicious content.
Once a qualifying Mac user reached the page, the victim could be instructed to paste a command into Terminal. The infection chain ultimately delivered information-stealing malware such as Atomic Stealer.
Microsoft also notes that macOS 26.4 and later includes a warning designed to block suspicious Terminal pastes that resemble these scams.
That protection helps, but employee awareness still matters.
How Can You Recognize a Fake CAPTCHA?
The most important warning sign is surprisingly simple.
A legitimate CAPTCHA should not ask you to run computer commands.
Be suspicious immediately if a website asks you to:
- Press Windows + R
- Open PowerShell
- Open Windows Terminal
- Open Command Prompt
- Open the macOS Terminal
- Paste a command
- Run a script
- Disable antivirus protection
- Change computer security settings
The Swiss NCSC specifically advises users never to run a computer command simply because a website tells them to do so. Instead, leave the website and seek IT assistance if necessary.
That rule is easy enough for almost any employee to remember.
CAPTCHAs belong in the browser. Computer commands do not.
What Should You Do If You See a Suspicious CAPTCHA?
Do not follow the instructions.
Close the browser tab.
Then report the website to your IT provider or security team.
If you already copied a command but did not execute it, clear your clipboard by copying something harmless.
When you actually ran the command, the situation changes.
If You Ran the Command
Stop normal work on the computer.
Then:
- Disconnect the computer from the network if your IT provider recommends doing so.
- Contact IT immediately.
- Tell them exactly what happened.
- Do not delete browser history or attempt to “clean things up.”
- Do not continue logging into business accounts from that machine.
- Be prepared to reset credentials if the investigation shows they may have been exposed.
Trying to hide an accidental click wastes valuable investigation time.
Security teams need accurate information.
What Should Small Businesses Do About ClickFix?
Technology alone will not solve this problem.
ClickFix succeeds because it makes a malicious instruction look like a legitimate task.
Therefore, businesses need both technical controls and employee education.
Microsoft recommends educating employees about fake CAPTCHA pages and restricting access to tools such as PowerShell and the Windows Run dialog where those tools are not required for normal work.
The Swiss NCSC also recommends current software, updated antivirus protection, MFA for website-management accounts, and employee awareness training.
For a small business, the practical security stack should include:
- Updated antivirus and endpoint protection
- Regular operating-system and software patching
- Network monitoring
- Multi-factor authentication
- Strong password management
- Secure backups
- Employee security training
- A clear incident-reporting procedure
No single layer stops every attack.
The goal is to make one employee mistake less likely to become a company-wide incident.
Teach Employees One Simple ClickFix Rule
Security training often fails because employees receive too many rules.
ClickFix gives businesses an opportunity to teach one very memorable one:
If a website asks you to open Run, PowerShell, Command Prompt, or Terminal, STOP.
Do not paste the command.
Do not press Enter.
And do not try to complete the verification.
Call IT.
That five-second decision may prevent hours or days of recovery work.
FAQ
Not exactly. ClickFix is primarily a social-engineering technique used to convince victims to execute malicious commands. Those commands can then install malware, information stealers, remote-access tools, or other payloads.
You should treat that instruction as highly suspicious. Normal CAPTCHA verification takes place inside the browser. The Swiss NCSC specifically advises users not to run commands because a website tells them to do so.
Antivirus and endpoint-security software can detect many components used in ClickFix attacks. However, the employee may be initiating the attack through legitimate operating-system tools. Therefore, endpoint protection should be combined with monitoring, patching, access controls, and employee education.
Yes. Current campaigns target both Windows and macOS systems. Microsoft documented sophisticated macOS ClickFix campaigns delivering information-stealing malware in August 2026.
Contact your IT or cybersecurity provider immediately. Do not assume that closing the browser fixed the problem. The command may already have downloaded additional malware or established access to the computer.
Proactive Security Starts With Knowing When to Stop
ClickFix demonstrates something every business should understand about cybersecurity.
Attackers do not always need to hack their way into a computer.
Sometimes they simply need to convince someone to open the door.
Fortunately, employee education can interrupt that process.
Teach your team that CAPTCHAs stay inside the browser. Keep computers patched. Maintain current endpoint protection. Monitor business systems. Most importantly, make sure employees know exactly who to contact when something feels wrong.
A few seconds of caution can stop a fake verification screen from becoming a real security incident.
If your team is unsure whether its current security protections and employee procedures are ready for threats like ClickFix, SofTouch Systems can help you review the basics and identify practical next steps.
Discover more from SofTouch Systems
Subscribe to get the latest posts sent to your email.