
A seemingly harmless page asks you to briefly confirm that you are not a machine. Click the tick box, then a report appears stating that the assessment has failed and you must complete it manually: press the keyboard shortcut, paste, then press Enter. What looks like a trivial technical step is, in fact, one of the most successful attack vectors of recent months. ClickFix does not turn software into an accomplice, but rather the person themselves, who carries out the malicious commands with their own hands.
ClickFix has rapidly evolved from a niche technique into a mass phenomenon. Microsoft now attributes around 47 per cent of observed attacks to this method. In this article, we explain how ClickFix works, why it bypasses traditional protection mechanisms, and what specific measures you can take to secure your business.
What ClickFix is and how the attack works
ClickFix is a Social Engineering technique in which attackers trick their victims into executing a malicious command on their own computer. The trick lies in disguising the execution as a solution to a supposed problem – for example, as a necessary step to view a page, open a document or complete a security check.
The typical sequence follows a clear pattern that specifically capitalises on everyday habits:
The bait
Via Phishing emails, manipulated adverts or hijacked websites, victims are directed to a rigged page that realistically mimics well-known services such as Google reCAPTCHA, Cloudflare Turnstile or Microsoft interfaces.
The fake assessment
A supposed human verification test appears. As soon as the victim clicks, a JavaScript script in the background silently copies an obfuscated command to the clipboard, whilst the page displays instructions for the supposed fix.
Manual execution
The victim is instructed to open the Run dialogue Win+R , paste the content using Strg+V and confirm by pressing Enter. This causes the command to run directly on the system.
The malware
The command uses built-in tools such as PowerShell to download malicious code. Amongst others, infostealers such as Lumma and Amatera, as well as remote access Trojans such as AsyncRAT and XWorm, have been identified.
The key point is this: it is not the technology that is being outwitted, but the human being. The victim carries out the attack themselves, thereby bypassing many layers of protection that are actually designed to prevent precisely this from happening.
Why ClickFix is so dangerous
ClickFix is not so effective because it uses particularly sophisticated malware, but because it shifts the point of compromise to precisely the stage at which traditional defences are of little use. Four characteristics make the method particularly insidious:
No attachment, no download
There is no suspicious file that a filter could block. The malicious code is only generated at the moment of execution by the victim.
Living off the land
The attack exploits legitimate built-in Windows tools such as PowerShell or signed scripts, which are present on and permitted by every system.
The user as the executor
Because the victim initiates the command themselves, the action appears to be a conscious, deliberate act rather than an attack from outside.
Kit-as-a-Service as a service provider
Ready-made ClickFix kits are rented out on the dark web for between 200 and 1,500 US dollars a month. This significantly lowers the barrier to entry for attackers.
Furthermore, the method is evolving rapidly. Alongside the classic ClickFix, variants such as FileFix, CrashFix and GlitchFix are now in circulation. Some campaigns use signed Windows components such as SyncAppvPublishingServer.vbsto make execution even more inconspicuous, and embed control commands in trusted services such as calendar entries.
What makes this particularly insidious is that the natural instinct to quickly sort out minor technical issues yourself becomes a point of entry. Technically savvy and helpful employees, in particular, are therefore not automatically protected – quite the opposite.
How to spot a ClickFix attempt
The good news is that ClickFix follows a recurring pattern. If you recognise the typical characteristics, you can stop the attack at the crucial moment. Look out for the following warning signs:
-
A request to copy and paste: No legitimate website and no genuine CAPTCHA will ever ask you to paste a command into the Run dialogue, PowerShell or the terminal.
-
Keyboard shortcuts as instructions: A page that gives you step-by-step
Win+R,Strg+Vand to press Enter almost always has malicious intentions. -
Urgency and alleged errors: Reports such as ‘Verification failed’, ‘Document cannot be loaded’ or ‘Browser needs updating’ are designed to pressure you into acting quickly and without thinking.
-
Familiar appearance, unusual step: Well-known logos and interfaces inspire trust, but the requested procedure does not match what the genuine service would ever ask for.
Rule of thumb for everyday use: As soon as a website asks you to enter something into the ‘Run’ dialogue or a command line, stop what you’re doing and report the incident to IT. This single rule prevents almost every ClickFix attack.
How to protect your business effectively
ClickFix targets people, which is why a combination of technical controls and trained employees is needed. Effective protection relies on several interlocking layers:
Reduce the attack surface
Restrict the ‘Run’ dialogue via Group Policy where it is not needed, set PowerShell execution policies and enable attack surface reduction rules against obfuscated scripts.
Detection and logging
Enable PowerShell Script Block Logging, monitor suspicious entries in the RunMRU registry, and deploy endpoint detection to identify suspicious process chains at an early stage.
Empowering people
Regular awareness training and realistic Phishing simulations that precisely replicate the ClickFix pattern. Employees who are aware of the trick are the strongest line of defence.
Clear reporting channels
A simple, hassle-free way to report suspicious websites and requests ensures that a single incident is spotted early on, before it spreads like wildfire.
Mint Secure GmbH
How Mint Secure supports you
We take a holistic view of ClickFix, from the technical hardening of your systems to the long-term strengthening of your security culture. In doing so, we focus on where the attack actually takes place.
Awareness & Simulation
Practical training courses and Phishing simulations that specifically practise the ClickFix approach and ensure your staff know exactly how to respond.
Technical Hardening
We review and configure group policies, ASR rules and logging to ensure that an accidental click has as little impact as possible.
Pentest & Assessment
Through controlled tests, we uncover just how vulnerable systems and processes really are to Social Engineering attacks such as ClickFix, and recommend clear measures.
Ready to get started? We offer a free initial consultation to assess your current situation and work with you to determine the next steps. Get in touch.
Conclusion
ClickFix is so successful because it targets the strongest yet most vulnerable element of your organisation: the helpful, solution-oriented individual. The attack requires no suspicious attachment and allows the victim to take the decisive step themselves. As a result, many traditional defences prove ineffective.
The best protection is a combination of technical hardening and a security culture that is actively practised. By helping your employees recognise the pattern whilst simultaneously reducing the attack surface through technical measures, you can neutralise most of ClickFix’s impact.
Mint Secure supports you every step of the way, from awareness training to technical hardening. Talk to us.

