KOM CLOUDSERVICE
All Insights

ClickFix: The Fake CAPTCHA That Gets Users to Infect Themselves

Attackers stopped sending malicious attachments. Now they talk your staff into pasting a command into Windows. Here is how ClickFix works and what stops it.

Getting someone to download and run an .exe file has gotten hard. Browsers warn. Windows warns. Users hesitate. So attackers stopped asking.

Instead they ask you to prove you’re not a robot. Huntress, which watches millions of endpoints and user identities, now runs this exact scenario in its security training because it is what they see criminals actually doing. And last week Malwarebytes flagged a variant called TerminalFix that looks like the same trick but drops a different payload. The technique has a name: ClickFix. If nobody in your office has seen it yet, they will.

How the trick actually works

Step one is an ordinary email. Usually a document that needs your signature. DocuSign is a favorite because everybody signs things and nobody thinks twice. There is no attachment to scan and no malware in the message, so it sails through most email filtering.

Step two is the click. The link goes to a real-looking page, and before the “document” loads, a verification overlay pops up. Prove you’re human.

Step three is where it goes wrong. The prompt does not ask for a checkbox. It asks the user to do three things:

  1. Press and hold the Windows key, then R.
  2. Press Ctrl + V.
  3. Press Enter.

That is it. Windows key + R opens the Run box. Ctrl + V pastes whatever the malicious page quietly copied to the clipboard when the user clicked. Enter runs it. The user just executed the attacker’s command with their own hands, on their own machine, with their own permissions.

No download prompt. No “this file may be harmful” banner. No admin password. The victim did every step voluntarily, and from the operating system’s point of view, a person sat at the keyboard and ran a command. Which is exactly what happened.

What that command does varies. Often it pulls down an info-stealer that scrapes saved browser passwords and session cookies, which is how attackers walk into your Microsoft 365 account later without ever guessing a password. TerminalFix uses the same setup and delivers something different, which is the point: ClickFix is a delivery method, not one specific piece of malware. Whoever rents it decides what lands.

Why your usual defenses miss this

This is the part worth sitting with, because most small businesses believe they are covered here and they are not.

Email filtering misses it. There is no attachment and no known-bad file. The first message is a link to a page that, at scan time, may look completely benign.

MFA does not apply. Nobody is logging in to anything. There is no authentication step to challenge. And if the payload steals session cookies, the attacker inherits an already-authenticated session anyway. We wrote about that problem in an earlier post, and it applies here too.

Basic antivirus often misses it. The command runs through legitimate Windows tools. Nothing suspicious got double-clicked. Signature-based scanning is looking for a file that never existed.

Your training probably misses it. Most awareness training teaches people to check the sender address, hunt for typos, and hover over links. Those habits are still good. They are also useless here, because the user is not being tricked into believing a fake login page. They are being tricked into doing routine-looking troubleshooting. It feels like something IT would tell them to do. That is the whole design.

What actually stops it

Three things, in order of how much they matter.

Tell every employee this one rule: no legitimate website ever asks you to press Windows + R. Not a CAPTCHA. Not a document viewer. Not a video player fixing an error. Never. If a web page gives you keyboard instructions that end with pasting something and hitting Enter, close the tab and tell whoever handles your IT. That single sentence, said out loud in a staff meeting, is worth more than an hour of generic training.

Run endpoint detection that watches behavior, not just files. EDR, meaning endpoint software that flags what a process is doing rather than what it is named, is the layer that catches a Run-box command reaching out to a strange server. It is the difference between finding out today and finding out when your bank account is short. That is a core piece of what we deploy for clients.

Rotate the credentials after any suspected incident. If someone ran the command, assume saved browser passwords and active sessions are gone. Reset passwords, revoke sessions in Microsoft 365, and check for new mail forwarding rules. Attackers set those up within minutes.

One more thing, cheap and effective: block the Run dialog for staff who never use it. Most people in an accounting office or a dental practice have never pressed Windows + R in their lives.

If you’re not sure whether your current setup would catch this, or whether anyone has already fallen for it, that’s a fair question to ask. Book a free 15-minute consult and we’ll tell you straight.

Talk to the person who'll actually run your IT.

Book a free 15-minute consult. No sales pitch from a stranger, just a straight conversation about what your business needs.

Book your free consult

Or call (732) 701-7012

Monthly agreements, not multi-year lock-ins  ·  No call centers, ever