Clickfix: What It Is and How to Avoid It

Scammers and hackers get sneakier all the time.

ClickFix is a scam that turns a simple "prove you're human" (or other fake message) pop-up into a malware trap, using your own keystrokes to install it. I'll discuss how it works, where you'll find it, and the one red flag that gives it away every time.
A close up over-the-shoulder perspective of a Corgi using a Windows computer with a "Prove you're a Corgi" message on screen.
(Image: Google Flow)

You’re surfing along on the internet, and you get another one of those “prove you’re human” pop-up messages. Instead of being an obscure “click every square that has a bicycle” CAPTCHA (yay?), this has instructions that are easy to follow: click here, type that, and prove your humanity.

You also installed malware on your device.

This one is sneaky.

TL;DR:

Avoiding ClickFix

ClickFix is a hacker’s trick that gets you to copy hidden code and paste it on your computer. That’s how it sneaks in malware. Remember: no real site ever needs you to paste anything. If you see that, stop.

Mockup of a ClickFix scam.
Mockup of a ClickFix scam. Click for larger image. (Image: Google Flow)

ClickFix

ClickFix works like this.

  • It presents a message that requires you to take some action, followed by some keystrokes or other actions.
  • The first action — clicking the box in the example above — silently copies malicious instructions, or a payload, onto your clipboard.
  • The subsequent actions cause those malicious instructions to be run. In the example above:
    • Windows Key + R opens the Windows “Run” dialog box.
    • CTRL+V pastes the clipboard contents — malicious instructions — into the Run dialog.
    • Enter causes those malicious instructions to be run.

You didn’t download anything shaky; you didn’t open an unknown attachment; you just followed instructions.

It works because it bypasses your antivirus and browser warnings — you’re the one running the payload. This example also exploits our familiarity and frustration with complex CAPTCHAs because it’s easier to follow.

Ask Leo! is Ad-Free!
Help keep it going by becoming a Patron.

ClickFix is the delivery; the payload is the goal

ClickFix itself is just a delivery mechanism. Its goal is to get you to run something malicious. That something is typically a download of some larger malware package.

What can that package do?

Depends on how it was written.

The symptoms of having fallen for a ClickFix delivery vary dramatically based on what your specific interaction downloaded and installed. It could be a silent password stealer, a spam bot, a cryptocurrency miner, or something more obviously destructive like ransomware.

ClickFix is just the bus it rode in on. Once delivered, it’s free to do what it wants.

Where you’ll find ClickFix

Legitimate sites that have been compromised are the most common places you’ll encounter ClickFix. But ClickFix can be found in all the normal scam/phishing sources:

  • Phishing emails
  • Fake Zoom/Teams install, update, or “fix” prompts
  • GitHub issue/comment lures
  • Fake browser-crash recovery screens
  • Fake software update or driver-fix pages

You get the idea. The answer to “Where can it be found?” is really “Anywhere”.

The big red flag

Fortunately, once you know how it works, there’s a huge red flag that tells you to stop.

Any instructions telling you to open Run, PowerShell, Command Prompt, or Terminal and paste something into it are malicious. Legitimate verification never requires this.

In fact, you can boil that down to a single, less complicated red flag: legitimate verification never asks you to paste. As soon as you see paste or CTRL+V or SHIFT+Insert1, stop. You’re done. Go no further.

If it’s already happened to you

If you’ve already run whatever ClickFix offered you, then you must assume that your computer has been compromised and you have malware.

Take steps to remove malware. I can’t be any more specific than that, because we don’t know what malware was downloaded and installed.

And, of course, learn from the experience.

Do this

Remember: no legitimate site or app ever needs you to open a system command prompt and paste anything to prove you’re human. As soon as you see instructions to paste anything anywhere, run away.

Subscribe to Confident Computing! Less frustration and more confidence, solutions, answers, and tips in your inbox every week.

Podcast audio

Play

Footnotes & References

1: Also another common, old-school keystroke for paste.

Think before you Click(Fix): Analyzing the ClickFix social engineering technique – Microsoft

3 comments on “Clickfix: What It Is and How to Avoid It”

  1. Hello, I routinely work on my friends’ computers to get them running again after problems you describe. One problem that seems to be missing from your excellent video is a situation where a “clickfix” comes up and does not allow the user to exit the program unless its instructions are followed. Because I, personally, know how to exit from such situations I find that most of my friends become stuck. They know clickfix is bad but cannot get past it. Do you have a video on that? It would be quite helpful! -KTP

    Reply
  2. Lately I’ve had notifications pop up in my web browser while going to my bank’s login page requesting permission to access my clipboard and more recently to access other apps on my computer. I decline every time becausethe bank has never expkained why they need this permission. I get this is different than what Leo described but it also highlights that you have to keep an eye on what is going on when you’re on the web.

    Reply

Leave a reply:

Before commenting please:

  • Read the article.
  • Comment on the article.
  • No personal information.
  • No spam.

Comments violating those rules will be removed. Comments that don't add value will be removed, including off-topic or content-free comments, or comments that look even a little bit like spam. All comments containing links and certain keywords will be moderated before publication.

I want comments to be valuable for everyone, including those who come later and take the time to read.