Scammers and hackers get sneakier all the time.

You’re surfing along on the internet, and you get another one of those “prove you’re human” pop-up messages. Instead of being an obscure “click every square that has a bicycle” CAPTCHA (yay?), this has instructions that are easy to follow: click here, type that, and prove your humanity.
You also installed malware on your device.
This one is sneaky.

Avoiding ClickFix
ClickFix is a hacker’s trick that gets you to copy hidden code and paste it on your computer. That’s how it sneaks in malware. Remember: no real site ever needs you to paste anything. If you see that, stop.

ClickFix
ClickFix works like this.
- It presents a message that requires you to take some action, followed by some keystrokes or other actions.
- The first action — clicking the box in the example above — silently copies malicious instructions, or a payload, onto your clipboard.
- The subsequent actions cause those malicious instructions to be run. In the example above:
+ R opens the Windows “Run” dialog box.
- CTRL+V pastes the clipboard contents — malicious instructions — into the Run dialog.
- Enter causes those malicious instructions to be run.
You didn’t download anything shaky; you didn’t open an unknown attachment; you just followed instructions.
It works because it bypasses your antivirus and browser warnings — you’re the one running the payload. This example also exploits our familiarity and frustration with complex CAPTCHAs because it’s easier to follow.
Help keep it going by becoming a Patron.
ClickFix is the delivery; the payload is the goal
ClickFix itself is just a delivery mechanism. Its goal is to get you to run something malicious. That something is typically a download of some larger malware package.
What can that package do?
Depends on how it was written.
The symptoms of having fallen for a ClickFix delivery vary dramatically based on what your specific interaction downloaded and installed. It could be a silent password stealer, a spam bot, a cryptocurrency miner, or something more obviously destructive like ransomware.
ClickFix is just the bus it rode in on. Once delivered, it’s free to do what it wants.
Where you’ll find ClickFix
Legitimate sites that have been compromised are the most common places you’ll encounter ClickFix. But ClickFix can be found in all the normal scam/phishing sources:
- Phishing emails
- Fake Zoom/Teams install, update, or “fix” prompts
- GitHub issue/comment lures
- Fake browser-crash recovery screens
- Fake software update or driver-fix pages
You get the idea. The answer to “Where can it be found?” is really “Anywhere”.
The big red flag
Fortunately, once you know how it works, there’s a huge red flag that tells you to stop.
Any instructions telling you to open Run, PowerShell, Command Prompt, or Terminal and paste something into it are malicious. Legitimate verification never requires this.
In fact, you can boil that down to a single, less complicated red flag: legitimate verification never asks you to paste. As soon as you see paste or CTRL+V or SHIFT+Insert1, stop. You’re done. Go no further.
If it’s already happened to you
If you’ve already run whatever ClickFix offered you, then you must assume that your computer has been compromised and you have malware.
Take steps to remove malware. I can’t be any more specific than that, because we don’t know what malware was downloaded and installed.
And, of course, learn from the experience.
Do this
Remember: no legitimate site or app ever needs you to open a system command prompt and paste anything to prove you’re human. As soon as you see instructions to paste anything anywhere, run away.
Subscribe to Confident Computing! Less frustration and more confidence, solutions, answers, and tips in your inbox every week.
Podcast audio
Footnotes & References
1: Also another common, old-school keystroke for paste.
Think before you Click(Fix): Analyzing the ClickFix social engineering technique – Microsoft



Hello, I routinely work on my friends’ computers to get them running again after problems you describe. One problem that seems to be missing from your excellent video is a situation where a “clickfix” comes up and does not allow the user to exit the program unless its instructions are followed. Because I, personally, know how to exit from such situations I find that most of my friends become stuck. They know clickfix is bad but cannot get past it. Do you have a video on that? It would be quite helpful! -KTP
There is an embeded video in this article.
Lately I’ve had notifications pop up in my web browser while going to my bank’s login page requesting permission to access my clipboard and more recently to access other apps on my computer. I decline every time becausethe bank has never expkained why they need this permission. I get this is different than what Leo described but it also highlights that you have to keep an eye on what is going on when you’re on the web.