Avatier

Phished or stolen credentials

ClickFix

Also called: fake CAPTCHA

ClickFix is a social engineering technique that tricks a user into running malicious commands on their own computer. A web page shows a fake error or CAPTCHA and tells the visitor to copy, paste and run a command to fix it. The command installs malware, which often steals saved passwords and session cookies.

How it works

The attacker places the lure on a compromised or fake website. The page quietly copies a command to the clipboard, then tells the visitor to open the Windows Run box, paste and press Enter as a verification step. Because the user runs the command, security tools can treat it as a legitimate action.

A real example

A July 2025 CISA and FBI advisory said Interlock ransomware actors were observed using the ClickFix technique for initial access and, in some instances, prompted users to run a malicious payload by clicking a fake CAPTCHA.

Source: #StopRansomware: Interlock (AA25-203A) — Cybersecurity and Infrastructure Security Agency (CISA), 2025-07-22

The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Phishing-resistant MFA and short session lifetimes limit what stolen passwords and cookies can do. Restrict who can run scripts and command-line tools on standard user devices.

Related terms

Sources

  1. #StopRansomware: Interlock (AA25-203A) — Cybersecurity and Infrastructure Security Agency (CISA), 2025-07-22

Last reviewed Oct 2, 2026