ClickFix Attacks Infect PCs and Macs With 1 Pasted Command via Fake CAPTCHAs
Updated
Updated · Ars Technica · Sep 11
ClickFix Attacks Infect PCs and Macs With 1 Pasted Command via Fake CAPTCHAs
3 articles · Updated · Ars Technica · Sep 11
Summary
Fake CAPTCHA prompts on compromised websites are pushing PC and Mac users to paste a single command into Windows Run, PowerShell or macOS Terminal, turning ClickFix from a niche trick into a mainstream infection method.
That spread rests on simplicity: attackers need only hijack a legitimate site, overlay a CAPTCHA—often posing as Cloudflare—and hide the malicious command well enough that users copy and run it.
Kevin Beaumont said Reddit is filling with reports of ClickFix infections and that legitimate websites are increasingly being hacked to serve the prompts, showing how broadly the tactic has taken hold.
The attacks exploit user fatigue with endless CAPTCHAs, pop-ups and shifting interfaces, making unusual instructions feel routine enough that even long-used websites can coax victims into infecting themselves.