ClickFix attacks infecting PCs and Macs are going viral

A new cyberattack technique called 'ClickFix' is spreading rapidly, tricking users into running malicious terminal commands by masquerading as fake CAPTCHA prompts. The attack exploits user fatigue and the increasing complexity of modern web interfaces.
Why it matters
This trend demonstrates how attackers are successfully weaponizing the 'user experience' friction of the modern web to bypass traditional security awareness.
THE NEW NORMAL ClickFix attacks infecting PCs and Macs are going viral Simplicity—combined with the difficulty of getting stuff done—makes ClickFix ideal.
64 Illustration of an infected laptop with tentacles. Credit: Getty Images Illustration of an infected laptop with tentacles. Credit: Getty Images Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav It wasn’t that long ago that ClickFix attacks were exotic. Now the technique has become mainstream as attackers reap its simplicity and effectiveness in infecting users of PCs and Macs alike. All that’s required is a compromised website—a painless enough task—a fake CAPTCHA overlay, and the inclusion of a single terminal command. So many visitors get suckered into pasting and running the command that just about every malware pusher has adopted the technique. Even Kremlin-backed hacking groups are joining in.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in