Family Sentinel
Threat Intelligence · September 14, 2026 · 15 min read

ClickFix: the "prove you're human" box that makes you infect your own computer

For thirty years, security advice came down to two rules: don't open strange attachments, and don't click strange links. A technique called ClickFix was built to walk straight past both — because it never sends you a file and never needs you to click a link. It shows you a small, ordinary-looking box that says you need to prove you're human or fix a loading error, gives you three keys to press, and lets you run the malware yourself, with your own hands, on the far side of your antivirus.

It works well enough that it went from a curiosity to one of the most common ways computers get infected in about a year. Security firm ESET measured a 517% increase in these attacks between the second half of 2024 and the first half of 2025, and reported they had become its second most common attack type, behind only ordinary phishing (ESET, H1 2025 Threat Report). Microsoft says it sees thousands of enterprise and home devices hit by it every day (Microsoft Threat Intelligence, August 2025). This post explains exactly how it works, shows you what it looks like, walks through every disguise it wears, and ends with the single rule that stops all of it.

How ClickFix grew up — a short timeline

The trick, in three keystrokes

Here is the whole attack. You are on a web page — maybe you searched for a document converter, maybe you clicked a link in an email, maybe a site you trusted was quietly compromised. A box appears that looks like the "I'm not a robot" checks you've clicked a thousand times. You click the checkbox. Instead of a green tick, the box expands and shows you a short, calm set of instructions: to finish verifying, press these keys.

A mock-up of a fake human-verification box with paste-and-run instructions Verify you are human Verification ID: 7F3A-22B9 · this check keeps our site secure To finish, complete these steps: 1. Press ⊞ Windows + R 2. Press Ctrl + V 3. Press Enter Ray ID: 9a1c7e0f4 · protected by verification
Our own re-creation of a ClickFix "verification" box. The "Verification ID" and "Ray ID" are decorative — they exist only to make a throwaway page feel like a real security check. No genuine verification has ever asked you to open the Run box.

What you cannot see is that the moment you clicked the checkbox, the page silently copied a command into your clipboard using ordinary browser code. Nothing downloaded. Nothing was flagged. The three steps do the rest:

That command reaches out to the attacker's server and pulls down the real malware — an information-stealer or a remote-control tool. The line is written to be unreadable: a wall of scrambled text and a Base64 blob, often padded with official-looking junk and a fake error code at the end so that if you glance at it, it reads like a harmless system string rather than a program (ANY.RUN; Microsoft). By the time anything lands on your machine, you have already told Windows it's allowed, because you typed it in yourself.

Why your antivirus never gets a vote

This is the part that makes ClickFix so effective, and it's worth understanding plainly. Antivirus and email filters are very good at catching a bad file arriving — an attachment, a download, a program with a suspicious signature. ClickFix never sends a file through those doors. The web page only writes text to your clipboard, which almost no security tool inspects. Then you open a trusted, built-in Windows tool and run the command by hand. To the computer, that looks like the owner doing ordinary work, not an attack (Microsoft, August 2025).

The ClickFix chain, showing where antivirus is bypassed Fake "verify"web page Command copiedto clipboard You paste + runit in Run box Command pullsdown malware Passwordsstolen antivirus watches here → …but the attack lives on this side of the line, run by your own hands
Antivirus is built to stop a malicious file arriving. ClickFix moves the whole attack to the right of that line — the browser only copies text, and you run the command yourself.

It also slips past the training most people have had. If you were taught "don't open attachments," this has no attachment. If you were taught "don't click links," you already followed the link before the trick even began. The instruction — press these keys to fix a problem — sounds like the opposite of danger. That is the whole design.

The same trick wears many costumes

The mechanism never changes: get you to run a command you didn't write. Only the disguise changes, and it changes constantly to match whatever you were already doing when you got caught.

DisguiseWhat you seeWhere you meet it
Fake CAPTCHA"Verify you are human" / "I'm not a robot," then paste-and-run stepsCompromised sites, malicious ads, search results
Fake Cloudflare checkA near-perfect copy of the Cloudflare "checking your browser" widget, with a fake "Ray ID"Pages disguised as news or download sites (Cybersecurity News)
Fake document error"This document failed to load" with a "How to fix" buttonHTML files disguised as Word docs, sent by email (Sekoia)
Fake browser/software updateA Chrome, Edge or "security update" promptHijacked WordPress sites; the Interlock ransomware lure (CISA)
Fake video meetingA "your microphone/camera driver needs a fix" screen on a fake Google MeetMeeting links in phishing emails (Sekoia, "Phantom Meet")
Fake Booking.com emailA "guest complaint" or "reservation" prompt to a fake verification pageHotel and hospitality inboxes (Microsoft, Storm-1865)
Fake job interviewA "coding assessment" you're asked to run on your machineDevelopers, via fake recruiter messages (Sekoia, Lazarus)
FileFixA file-upload window; you're told to paste a "file path" into the address barNewer sites; used to dodge people trained on the Run box (Check Point)
Mac / Terminal"Open Terminal and paste this to repair"Fake Mac utility and repair-tool pages (Kaspersky, Microsoft)

FileFix deserves a special mention, because it targets people who learned the first lesson. Once "never use Win+R when a website tells you to" started spreading, attackers moved the trap. FileFix opens a window that looks like an ordinary "choose a file to upload" dialog and tells you to paste a file path into the address bar at the top — except the "path" is a disguised command. It was disclosed in June 2025 and criminals were caught testing it within two weeks; the Interlock ransomware group adopted it specifically to reach users who had been trained to distrust the Run box (Check Point; Taggart Tech). The lesson is not "beware the Run box." The lesson is broader, and it's below.

What it steals

The command that runs is only the doorway. What comes through it is usually an information-stealer — malware families with names like Lumma, Vidar and StealC, and on Mac, Atomic Stealer (Microsoft; Proofpoint; Kaspersky). In seconds, quietly, these programs harvest:

In an organization, that first infected machine is often just the beginning: the same access is used to spread and, in the Interlock cases the FBI documented, to launch ransomware across the network (CISA AA25-203A).

The one rule that stops all of it

No real security check ever asks you to press Windows+R, open Terminal, or paste anything outside a normal web form. Never copy a command from a web page, an email, a pop-up, a video, or a phone caller and run it — no matter how official the "fix" looks or how urgent it sounds. A genuine "prove you're human" test is a puzzle or a checkbox. It is never a set of keys to press on your own keyboard.

How to spot it, in the moment

If you already did it

It happens to careful people; the trick is engineered to make it happen. Move quickly and calmly:

  1. Disconnect that computer from the internet — unplug the cable or turn off Wi-Fi — to cut the malware off from the attacker.
  2. From a different, trusted device (a phone, another computer), change the passwords for your email first, then banking, then anything whose password was saved in that browser. Do not use the infected machine to do it.
  3. Check your bank and any crypto accounts for activity you don't recognize, and call your bank's fraud line.
  4. Have the machine professionally wiped and reinstalled, not just "cleaned." Stealers are designed to leave little behind, so a scan coming back clean is not proof it's gone.
  5. Turn on or re-confirm two-factor authentication everywhere after the passwords are changed, since stolen sessions are now invalid once passwords reset.

For families protecting an older parent

This attack depends entirely on a person following instructions, which makes it especially dangerous for anyone inclined to trust an official-looking screen. It is the same shape as the tech-support scams the FBI warns seniors about — a fake urgent problem, an urgent "fix," a stranger's instructions — except there's no live scammer on the phone, just a web page (FBI). The single household rule worth teaching, in plain words:

Say this to the person you're protecting

For a small business or city office

Because ClickFix hits any organization with staff and computers, a few practical controls matter more than they look:

Related reading

The scam that reaches your parent usually comes by email first.

Family Sentinel watches an older loved one's inbox around the clock — reading what a message is actually trying to get them to do, following links to where they truly land, and calling a human before a scam ever reaches your family. Quiet, read-only, and built for the people most targeted.

Start your free month →

Get the next threat breakdown before it reaches you.

Our Threat Intelligence notes go out regularly — plain, current, and free.

Written by the Family Sentinel security desk — a working Security Architect and the team who watch business and family inboxes around the clock. Sources: Microsoft Threat Intelligence (2025–2026); ESET H1 2025 Threat Report; Proofpoint; Check Point Research; Sekoia; Kaspersky; Jamf Threat Labs; Malwarebytes; CISA advisory AA25-203A; FBI; Krebs on Security. Illustrations are our own re-creations, not copies of live attack pages.