ClickFix
Also called: fake CAPTCHA
ClickFix is a social engineering technique that tricks a user into running malicious commands on their own computer. A web page shows a fake error or CAPTCHA and tells the visitor to copy, paste and run a command to fix it. The command installs malware, which often steals saved passwords and session cookies.
How it works
The attacker places the lure on a compromised or fake website. The page quietly copies a command to the clipboard, then tells the visitor to open the Windows Run box, paste and press Enter as a verification step. Because the user runs the command, security tools can treat it as a legitimate action.
A real example
A July 2025 CISA and FBI advisory said Interlock ransomware actors were observed using the ClickFix technique for initial access and, in some instances, prompted users to run a malicious payload by clicking a fake CAPTCHA.
Source: #StopRansomware: Interlock (AA25-203A) — Cybersecurity and Infrastructure Security Agency (CISA), 2025-07-22
The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Phishing-resistant MFA and short session lifetimes limit what stolen passwords and cookies can do. Restrict who can run scripts and command-line tools on standard user devices.
Related terms
Sources
- #StopRansomware: Interlock (AA25-203A) — Cybersecurity and Infrastructure Security Agency (CISA), 2025-07-22
Last reviewed Oct 2, 2026