Most of us have become pretty good at following instructions online. Tick the box to prove you’re human,  refresh the page to fix an error, copy and paste a verification code. Usually, these little prompts are harmless, and we get through them without giving them much thought because we want to get back to whatever we were trying to do. 

ClickFix attacks take advantage of that behaviour. Rather than asking someone to download a suspicious attachment or hand over their password, the attacker presents them with a problem and then helpfully provides the “solution”. The employee follows the instructions, believing they’re fixing an error or completing a routine verification step, but in doing so they can end up carrying out part of the attack themselves. 

It’s a clever twist on social engineering, and one that shows why spotting cyber threats increasingly requires employees to think beyond the phishing warning signs they’ve learned in the past. 

Table of Contents

    1. What Is a ClickFix Attack?
    2. How Do ClickFix Attacks Work?
    3. Why Are ClickFix Attacks So Convincing?
    4. Why ClickFix Doesn’t Look Like Traditional Phishing
    5. How to Spot a ClickFix Attack
    6. How Can Organisations Protect Employees Against ClickFix?
    7. Prepare Your Employees for the Attacks They’ll See Next
    8. Frequently Asked Questions

What Is a ClickFix Attack?

ClickFix is a social engineering technique that tricks people into running malicious commands on their own devices. The attack will often begin with something fairly ordinary, such as a website that won’t load properly, a fake CAPTCHA, a supposed browser problem or a message claiming that an error needs to be fixed. 

The victim is then given a series of instructions which might ask them to copy something, open a tool such as Windows Run or PowerShell, paste in a command and execute it. In some attacks, interacting with the page secretly places the malicious command onto the person’s clipboard before they’re told to paste it. 

Because the instructions are presented as the solution to a problem, the person may believe they’re completing a legitimate troubleshooting process. Following those steps, however, can trigger the next stage of the attack, such as downloading malware or giving an attacker access to sensitive information. 

How Do ClickFix Attacks Work?

There’s no single ClickFix template. Attackers can change the website, message, branding and instructions depending on who they’re targeting, which means an employee won’t necessarily see  the same warning signs from one attack to another. 

A typical attack might begin when an employee follows a link or visits a compromised website and is presented with what looks like a familiar verification screen. Perhaps there’s a CAPTCHA asking them to prove they’re human, or an error message telling them that something has gone wrong. The page then provides instructions to resolve the problem, which could involve opening a system tool and pasting in a command that has already been copied to their clipboard. 

This is where ClickFix becomes particularly interesting. The attacker isn’t relying solely on somebody clicking something they shouldn’t. They’re persuading the person to take a series of actions because those actions appear to be solving the problem in front of them. 

Why Are ClickFix Attacks So Convincing?

Imagine you’re trying to access a document before a meeting and a verification box appears with three steps you need to complete before you can continue. Your first thought probably isn’t that you’re in the middle of a cyber attack, so you’re much more likely to want to get through the instructions and carry on with your day. 

ClickFix works because many of the behaviours involved already feel normal. We’re used to websites asking us to complete CAPTCHAs, software giving us troubleshooting instructions and online services walking us through problems step by step. Copying and pasting is something most employees do dozens of times a day, so that action alone is unlikely to set alarm bells ringing. 

There’s also something reassuring about being given clear instructions when something isn’t working. The employee doesn’t have to figure out what’s wrong or search for a solution; the answer is conveniently sitting in front of them. Add a little urgency, such as telling them that verification is required before they can continue, and their attention is naturally drawn towards completing the task rather than questioning why they’re being asked to do it. 

That combination of familiarity and convenience is what makes the technique so convincing. The employee thinks they’re solving a problem, while the attacker is quietly guiding them through the steps needed to progress the attack. 

Why ClickFix Doesn’t Look Like Traditional Phishing

For years, employees have been taught some very sensible phishing rules: be careful with unexpected attachments, check links before clicking them, look closely at the sender and be suspicious when somebody unexpectedly asks for a password. Those habits are still valuable, but attacks like ClickFix show why employees also need to be prepared for threats that don’t follow such a familiar pattern. 

Someone could remember all of the traditional warning signs and still be caught out by ClickFix. They might not be asked for a password, there may be no suspicious attachment and the dangerous action could happen after they’ve reached a convincing website and started following what appear to be legitimate instructions. 

Attackers change their methods as people become better at recognising existing ones. Security awareness therefore needs to help employees understand how their manipulation works and recognise when a seemingly ordinary interaction starts moving in an unusual direction. Trying to memorise every possible attack format isn’t realistic, particularly when those formats continue to change. 

How to Spot a ClickFix Attack

The good news is that employees don’t need to become experts in PowerShell or understand exactly what every command does. What’s more useful is being able to recognise the point at which an ordinary online interaction starts asking them to do something unusual. 

A CAPTCHA asking someone to tick a box is familiar. A CAPTCHA asking them to open Windows Run andlaunchPowerShell and paste a command should prompt a very different reaction. Employees should be encouraged to stop when a website unexpectedly asks them to open system tools, copy and paste commands, bypass warnings, change security settings or perform technical actions they don’t understand. 

It’s also important that employees know what to do next. If something feels unusual, reporting it should be quick and straightforward, with a culture that encourages people to ask rather than worrying that they’re wasting the security team’s time. A few seconds spent checking an unexpected request is considerably easier to deal with than an employee unknowingly executing malicious code. 

How Can Organisations Protect Employees Against ClickFix?

ClickFix is a good example of how quickly social engineering techniques can change. Attackers don’t work from the same phishing template forever, which means employees need regular exposure to the techniques they’re likely to encounter now, alongside the skills to recognise manipulation when the scenario is unfamiliar. 

That means going beyond simply showing employees examples of known attacks. Awareness programmes can also help people understand the behaviours attackers are trying to encourage and give them practical questions to ask when something doesn’t feel right. Why is this website asking me to do this? Would a legitimate CAPTCHA normally require me to open a system tool? Do I understand what I’m about to paste into my computer? Is there another way I can verify whether these instructions are genuine? 

The aim isn’t to make employees suspicious of every CAPTCHA or error message they encounter, but to build a healthy instinct to stop what they’re doing when a familiar process takes an unfamiliar turn, particularly when they’re being asked to do something outside the browser or carry out technical steps they wouldn’t normally expect. 

As social engineering evolves, that ability to recognise manipulation becomes increasingly valuable. The next attack an employee encounters may look nothing like the phishing email they were shown six months ago, but they can still be prepared to recognise when someone is trying to steer their behaviour in the wrong direction. 

Prepare Your Employees for the Attacks They’ll See Next

As attackers continue to develop new social engineering techniques, employees need the knowledge and confidence to recognise suspicious requests, even when they appear to be part of a familiar everyday task. 

To help organisations prepare, MetaCompliance has introduced new ClickFix security awareness training covering three common attack scenarios: fake CAPTCHAs, blocked content and fraudulent software update instructions. These engaging learning experiences help employees understand how attackers manipulate everyday behaviours, recognise the warning signs and know when to stop and report something suspicious. 

Alongside our dedicated ClickFix training, Automated Security Awareness and Advanced Phishing Simulation help organisations deliver relevant, ongoing education and build stronger security behaviours across their workforce. 

Want to prepare your employees for evolving social engineering threats? Book a personalised demo to discover how MetaCompliance can help strengthen your security awareness programme. 

Frequently Asked Questions

What is ClickFix?

ClickFix is a social engineering technique where attackers trick people into running malicious commands on their own devices. It often uses fake error messages, CAPTCHAs or verification screens that provide instructions for supposedly fixing a problem.