ClickFix Attacks Infecting PCs and Macs Go Viral
ClickFix attacks are now mainstream, infecting PCs and Macs through fake CAPTCHA prompts on compromised websites, researcher Kevin Beaumont says.
ClickFix attacks have gone from a niche trick to a full-blown epidemic, and the numbers tell a story that security researchers are struggling to keep up with. What was once an exotic technique is now the go-to method for malware distributors targeting both Windows and Mac users. The barrier to entry is almost nonexistent: compromise a website, slap a fake CAPTCHA on it, and wait for visitors to paste a malicious command into their terminal. That’s it.
From Obscure Trick to Mainstream Plague
The scale of the problem became impossible to ignore. Kevin Beaumont saw it. The independent researcher observed Thursday what he was seeing, and what he was seeing was post after post after post of people getting their computer infected via ClickFix, a pattern he described in plain terms. "Reddit is becoming post after post after post of people getting their computer infected via ClickFix," he observed Thursday. And it's not just Reddit. "Legit websites everywhere [are] getting hacked to serve the fake captcha prompts.
That last part is what makes ClickFix attacks so dangerous. Victims don't wander into dark corners. They're visiting sites they've trusted for years, the same bookmarks they've clicked a thousand times without a second thought. A compromised website is all it takes. And compromising websites isn't exactly a heavy lift for determined attackers.
How the Scam Actually Works
The mechanics are almost insultingly simple. A user lands on a compromised site. They see what looks like a CAPTCHA box. It's often styled to resemble Cloudflare's verification widget, that familiar little checkbox people have clicked a million times without a second thought. After clicking it, a line of text appears. And it's typically obscured or partially hidden to mask the malicious commands embedded within it. Copy that text. Paste it into the Windows Run dialog, PowerShell, or the macOS terminal, then hit Enter.

The instructions look familiar. They resemble the hoops people have been jumping through for years. Why would someone without deep security knowledge hesitate?
“The pivot to ClickFix in late May 2026 eliminates the code-signing requirement entirely, substituting the legitimacy of a validly signed installer with a different form of legitimacy: a user voluntarily executing the malicious command in their own terminal.”
That assessment from security firm BlueVoyant captures the grim efficiency of the model. Before ClickFix, attackers needed resource-intensive infrastructure: SEO-manipulated download portals, malvertised ads, Microsoft-trusted signing certificates, and constantly rotated domains to deliver installer packages. All of that is now optional. The user does the heavy lifting.
Why Victim-Blaming Misses the Point
Plenty of seasoned internet users roll their eyes at ClickFix attacks. They blame the victims. They marvel at their gullibility. And it's easy to sit there feeling clever when you've spent years online and you think you'd never click something that obvious. But the truth is that these seasoned users are missing something fundamental about how the modern web, with all its endless prompts and pop-ups and urgent warnings, has worn down ordinary users.
Think about what casual computer use looks like today: interstitials that refuse to close, CAPTCHAs that demand endless rounds of identifying traffic lights, interfaces that shift and bury basic features. People have grown desensitized. Instructions that once seemed ridiculous now feel like just another hoop. ClickFix attackers are capitalizing on that fatigue, and they’re doing it at scale.
The Mac Illusion of Safety
Apple users might assume they’re insulated from this mess. They’re not. Both Mac security firm Jamf and an independent researcher have documented macOS variations of ClickFix attacks that can bypass Gatekeeper protections. The terminal is just as accessible on a Mac, and the social engineering works just as well.
Attackers keep finding new delivery methods. Cisco Talos has documented ClickFix campaigns abusing publicly published Google Sheets documents, while Russia's state-sponsored Sandworm group has been hosting command infrastructure in blockchain-based smart contracts, and security firm Netskope recently uncovered another campaign using the same approach, counting 5,400 sites calling back to it. That number alone hints at the reach. It's just one operation. And we've barely seen the scope.
What Actually Helps
There are defenses, though they require some effort. BlockBlock, a tool that monitors Macs for processes attempting to permanently install themselves, can block ClickFix attacks the moment a user presses the ⌘+V keys. Ublock has been updated to offer similar protection.
Beyond software, the most effective countermeasure might be conversation. Those with security training should build awareness with less experienced neighbors, family members, and friends. The mass adoption of ClickFix attacks demonstrates their success, and every indication suggests they aren’t going anywhere. Defenders build new walls. Attackers find documented ways around them. The cycle continues.
- ClickFix attacks rely on fake CAPTCHA prompts and user-pasted terminal commands.
- Both Windows and macOS systems are vulnerable, with Gatekeeper bypasses documented.
- Defenses like BlockBlock and Ublock can interrupt the attack chain.
The technique’s simplicity is its greatest strength. No code-signing certificates. No elaborate domain rotation. Just a compromised website, a fake verification box, and a user willing to follow instructions. Until that equation changes, ClickFix attacks will keep spreading.
Frequently Asked Questions
What makes ClickFix attacks so dangerous according to the article?
ClickFix attacks are dangerous because victims don't wander into dark corners; they're visiting sites they've trusted for years. Legit websites everywhere are getting hacked to serve the fake captcha prompts, and a compromised website is all it takes.
How does the ClickFix scam actually work mechanically?
A user lands on a compromised site and sees what looks like a CAPTCHA box, often styled to resemble Cloudflare's verification widget. After clicking it, a line of text appears that is typically obscured to mask malicious commands, which the user copies and pastes into the Windows Run dialog, PowerShell, or the macOS terminal, then hits Enter.
When did the pivot to ClickFix occur and what did it eliminate?
According to security firm BlueVoyant, the pivot to ClickFix in late May 2026 eliminates the code-signing requirement entirely. It substitutes the legitimacy of a validly signed installer with a different form of legitimacy: a user voluntarily executing the malicious command in their own terminal.
Who has documented macOS variations of ClickFix attacks that bypass Gatekeeper protections?
Both Mac security firm Jamf and an independent researcher have documented macOS variations of ClickFix attacks that can bypass Gatekeeper protections. The terminal is just as accessible on a Mac, and the social engineering works just as well.
What defenses can actually help interrupt ClickFix attacks?
BlockBlock, a tool that monitors Macs for processes attempting to permanently install themselves, can block ClickFix attacks the moment a user presses the ⌘+V keys, and Ublock has been updated to offer similar protection. Beyond software, the most effective countermeasure might be conversation, as those with security training should build awareness with less experienced neighbors, family members, and friends.
💬 Comments (0)
No comments yet. Be the first!













