Today we'll talk about yet another hacking evolution that continues letting cyber criminals into your organization: the ClickFix attack. This trick has exploded over the last two years to the tune of a 500% jump in ClickFix attacks in the first half of 2025 alone. It's now the second most common way attackers get their first foothold in a business, right behind phishing emails.
We're breaking this one down because it's the delivery method for the exact problem we cover in our guide to business credential theft: infostealer malware that grabs saved passwords straight off an employee's computer. If you want to stop that problem at the source, you need to understand how it gets in.
A ClickFix attack is a social engineering technique where a fake error message, CAPTCHA, or verification page convinces a user to copy a command to their clipboard and paste it into a place where a computer will run it, usually the Windows Run box, PowerShell, or Terminal. The moment the employee hits enter, the command downloads and installs the attacker's real malware.
As opposed to other types of attacks, no file gets downloaded and no link gets clicked, which is what makes this technique so effective. The employee types the command themselves using tools that are already on their computer for legitimate reasons.
A ClickFix attack usually runs in three steps:
ClickFix works because it borrows the exact motions of real IT troubleshooting. Pasting a command into Run or a terminal to fix a stuck program is something a lot of employees have been instructed to do by their own IT team before. The fake prompt asks them to solve their own problem, and that framing turns off the skepticism most phishing training tries to build.
It also skips the parts of a computer's defenses built to catch a download. Traditional antivirus and email filters are built to catch malicious attachments and links. A ClickFix attack doesn't deliver a file at all in that first step. It delivers a set of instructions, and the employee's own hands do the rest. That's a big part of why the numbers have climbed drastically since 2025: it's currently outrunning a lot of the security tools built to catch older tricks.
Once the command runs, the most common payload is infostealer malware, the same category of program behind most credential theft cases we see, including Lumma Stealer, which pulls saved passwords, browser cookies, and even active login sessions straight off the machine. From there, an attacker can log into email, banking, or business software using credentials the employee never even realized were stolen, a problem we cover in more detail in our post on how session hijacking bypasses MFA.
Infostealers aren't the only payload showing up. Remote access trojans give an attacker hands-on control of the machine, and CISA has directly tied ClickFix tactics to Interlock ransomware attacks hitting businesses across the country. What starts as one employee "fixing an error" can end with an attacker sitting inside your network, working their way toward every system that machine has access to.
Your team doesn't need to become security experts to catch this one. A few rules cover almost every version of this scam:
Protecting your business from ClickFix attacks takes two things working together: training that specifically covers this scam, since generic phishing training doesn't, and technical controls that limit what a regular employee's account is allowed to run in the first place.
On the training side, this means showing your team what a real ClickFix prompt looks like, not just talking about phishing emails in the abstract. We run ongoing phishing and social engineering simulations for our clients that include newer tricks like this one, and anyone who misses a test gets flagged for quick, targeted follow-up instead of a once-a-year training video nobody remembers.
On the technical side, most employees never need to run PowerShell scripts or type commands into the Run box. Locking that down at the account level, combined with endpoint protection tuned to catch this exact pattern of behavior, closes the door even if someone does get fooled. That's the kind of layered setup our fractional IT services build into every client environment from day one, not bolted on after something goes wrong.
If someone on your team already ran a command they're unsure about, don't wait to find out if it was serious. Disconnect the machine from the network and call your help desk team right away. The faster that machine gets isolated, the less time an attacker has to move.
ClickFix works because it turns your own employees into the delivery method, and it's not slowing down. The good news is the fix isn't complicated: train your team to spot the specific signs, and lock down what an average account can actually run. That combination stops this attack cold, whether it shows up as a fake CAPTCHA, a bogus error message, or whatever variation comes next.
If you're not sure how your current setup would hold up against a ClickFix attempt, we'll walk through it with you.