Blog - IT & Cybersecurity News | TMGC

What Is a ClickFix Attack? The Trick Fooling Employees Into Installing Malware

Written by Tony DiDonato | Aug 28, 2026, 8:59:19 PM

Today we'll talk about yet another hacking evolution that continues letting cyber criminals into your organization: the ClickFix attack. This trick has exploded over the last two years to the tune of a 500% jump in ClickFix attacks in the first half of 2025 alone. It's now the second most common way attackers get their first foothold in a business, right behind phishing emails.

We're breaking this one down because it's the delivery method for the exact problem we cover in our guide to business credential theft: infostealer malware that grabs saved passwords straight off an employee's computer. If you want to stop that problem at the source, you need to understand how it gets in.

 

Key Takeaways

  • A ClickFix attack tricks a user into copying and pasting a malicious command into their own computer, believing they're completing a normal verification step or fixing an error.
  • It works because it looks like everyday tech troubleshooting and skips right past antivirus software since the user runs the command themselves.
  • Attacks are up 500+ % year over year, and the payload is often the same infostealer malware behind most credential theft and ransomware cases.
  • The fix is a mix of specific employee training (not just for phishing) and technical guardrails that limit what a regular employee's account can run.
  • TMGC builds both pieces into every client's security program, so this isn't something you have to figure out or roll out alone.

Table of Contents

  1. What Is a ClickFix Attack?

  2. How Does a ClickFix Attack Work?

  3. Why This Trick Fools Careful Employees

  4. What Happens After Someone Clicks "Fix"?

  5. Warning Signs Your Team Should Know

  6. How to Protect Your Business From ClickFix Attacks

 

What Is a ClickFix Attack?

A ClickFix attack is a social engineering technique where a fake error message, CAPTCHA, or verification page convinces a user to copy a command to their clipboard and paste it into a place where a computer will run it, usually the Windows Run box, PowerShell, or Terminal. The moment the employee hits enter, the command downloads and installs the attacker's real malware.

As opposed to other types of attacks, no file gets downloaded and no link gets clicked, which is what makes this technique so effective. The employee types the command themselves using tools that are already on their computer for legitimate reasons.

 

How Does a ClickFix Attack Work?

A ClickFix attack usually runs in three steps:

  1. An employee gets an email, sees a malicious ad, or lands on a compromised website that mimics a service they trust, like Google, Cloudflare, or DocuSign
  2. The page shows a "verify you're human" prompt or an error message claiming a document or download failed.
  3. When they click the button to fix it, a command gets silently copied to their clipboard, not anything they typed themselves.
  4. The page then walks them through the "fix": press Windows key + R, paste, hit enter. Or open PowerShell and paste. Once the command runs, it usually downloads a script that installs the actual malware in the background while the user goes about their day, none the wiser.

 

Why This Trick Fools Careful Employees

ClickFix works because it borrows the exact motions of real IT troubleshooting. Pasting a command into Run or a terminal to fix a stuck program is something a lot of employees have been instructed to do by their own IT team before. The fake prompt asks them to solve their own problem, and that framing turns off the skepticism most phishing training tries to build.

It also skips the parts of a computer's defenses built to catch a download. Traditional antivirus and email filters are built to catch malicious attachments and links. A ClickFix attack doesn't deliver a file at all in that first step. It delivers a set of instructions, and the employee's own hands do the rest. That's a big part of why the numbers have climbed drastically since 2025: it's currently outrunning a lot of the security tools built to catch older tricks.

 

What Happens After Someone Clicks "Fix"?

Once the command runs, the most common payload is infostealer malware, the same category of program behind most credential theft cases we see, including Lumma Stealer, which pulls saved passwords, browser cookies, and even active login sessions straight off the machine. From there, an attacker can log into email, banking, or business software using credentials the employee never even realized were stolen, a problem we cover in more detail in our post on how session hijacking bypasses MFA.

Infostealers aren't the only payload showing up. Remote access trojans give an attacker hands-on control of the machine, and CISA has directly tied ClickFix tactics to Interlock ransomware attacks hitting businesses across the country. What starts as one employee "fixing an error" can end with an attacker sitting inside your network, working their way toward every system that machine has access to.

 

Warning Signs Your Team Should Know

Your team doesn't need to become security experts to catch this one. A few rules cover almost every version of this scam:

  1. A real website, software update, or verification step will never ask someone to open the Run box, PowerShell, or Terminal and paste something in.
  2. "I'm not a robot" checks don't require copying or pasting anything. If a CAPTCHA gives you instructions instead of just a checkbox or picture puzzle, that's the scam.
  3. Error messages that tell you exactly how to "fix" the problem yourself, especially with a keyboard shortcut and a paste command, deserve a second look before anyone acts on them.
  4. If a coworker isn't sure whether something is legitimate, the answer is always to stop and ask, not to guess.

 

How to Protect Your Business From ClickFix Attacks

Protecting your business from ClickFix attacks takes two things working together: training that specifically covers this scam, since generic phishing training doesn't, and technical controls that limit what a regular employee's account is allowed to run in the first place.

On the training side, this means showing your team what a real ClickFix prompt looks like, not just talking about phishing emails in the abstract. We run ongoing phishing and social engineering simulations for our clients that include newer tricks like this one, and anyone who misses a test gets flagged for quick, targeted follow-up instead of a once-a-year training video nobody remembers.

On the technical side, most employees never need to run PowerShell scripts or type commands into the Run box. Locking that down at the account level, combined with endpoint protection tuned to catch this exact pattern of behavior, closes the door even if someone does get fooled. That's the kind of layered setup our fractional IT services build into every client environment from day one, not bolted on after something goes wrong.

If someone on your team already ran a command they're unsure about, don't wait to find out if it was serious. Disconnect the machine from the network and call your help desk team right away. The faster that machine gets isolated, the less time an attacker has to move.

ClickFix works because it turns your own employees into the delivery method, and it's not slowing down. The good news is the fix isn't complicated: train your team to spot the specific signs, and lock down what an average account can actually run. That combination stops this attack cold, whether it shows up as a fake CAPTCHA, a bogus error message, or whatever variation comes next.

If you're not sure how your current setup would hold up against a ClickFix attempt, we'll walk through it with you.