A staff member clicks a link, or just opens a website they use every week. A box appears saying "verify you are human". Instead of picking traffic lights, it asks them to press the Windows key and R, then Ctrl and V, then Enter. It looks like a quirky security check. It is actually the person installing malware on their own computer.
This trick is called ClickFix. Microsoft and the Australian Cyber Security Centre (ACSC) have both tracked it since early 2024, and it has grown fast since. In August 2025 Microsoft said it was seeing ClickFix campaigns aimed at thousands of devices every day. In May 2026 the ACSC warned that criminals had broken into legitimate Australian WordPress websites and planted fake verification prompts on them, which delivered an information stealer called Vidar. So "only visit sites you trust" is not enough advice here.
How worried should you be? Fairly. It's cheap for attackers, it works on smart people, and the controls that stop it are mostly settings you already own.
How it works
The fake page quietly copies a command to the clipboard the moment the person clicks the checkbox or button. The instructions then walk them through pasting it somewhere that runs commands: the Windows Run box (Win + R), PowerShell or Windows Terminal. On a Mac, the same trick asks people to paste into Terminal.
Because the person runs the command themselves, it skips a lot of the checks that would catch a dodgy download. The command usually fetches the real payload from the internet. Microsoft's research names information stealers such as Lumma Stealer as common payloads. Those go after saved passwords, browser cookies and anything else worth selling. In July 2025 a joint advisory from CISA, the FBI and others said the Interlock ransomware group was using ClickFix to get its first foothold.
The trick keeps changing shape:
- FileFix, published by a security researcher in June 2025, uses a website's "upload a file" button to open File Explorer and asks the person to paste a "file path" into the address bar. The path is really a PowerShell command. Check Point saw attackers testing it just over two weeks later.
- CrashFix, reported by Microsoft in February 2026, starts with a fake ad blocker extension that deliberately crashes the browser, then offers a "fix" that is the malicious command.
- Mac campaigns now hide the lure from anyone who doesn't look like a real Mac user, which makes them harder for security tools to spot. Microsoft described one in August 2026.
The lure changes. The ask doesn't: copy this, paste it there, press Enter.
Are you affected?
If your staff use Windows or macOS computers and browse the web, yes. Warning signs to tell people about:
- A CAPTCHA or "browser check" that asks you to press keys, open anything, or paste anything.
- A page saying a document, meeting or update "failed" and giving you steps to fix it yourself.
- Being told to open File Explorer and paste a path someone gave you.
The simplest rule, and the one to put in your next staff email: no real website ever asks you to run a command to prove you're human. If a page asks, close it and tell IT.
How to fix it
Training helps, but you want settings that work on the day someone is tired and in a hurry. In rough order of value for a typical Microsoft 365 business:
- Remove the Run box for standard users. In Group Policy (or the equivalent Intune setting) it's User Configuration, Administrative Templates, Start Menu and Taskbar, "Remove Run menu from Start Menu". This also disables Win + R. It will annoy the two people who use the Run box. That's a good trade.
- Stop ordinary users launching PowerShell and the other script tools they never need. The strong way to do this is application control, using App Control for Business (formerly WDAC) or AppLocker. Microsoft specifically suggests an App Control rule that stops the Run box launching PowerShell. Application control is also an Essential Eight strategy, so the work counts twice. Our Essential Eight maturity levels explainer covers where it sits.
- Turn on attack surface reduction (ASR) rules in Microsoft Defender for Endpoint. Microsoft recommends three for ClickFix: block execution of potentially obfuscated scripts, block executable files unless they meet a prevalence, age or trusted list criterion, and block JavaScript or VBScript from launching downloaded executable content. Run them in audit mode for a week or two, check what they would have blocked, then enforce.
- Keep Defender's cloud-delivered protection, network protection and web protection on. Defender has specific detections for ClickFix behaviour, and network protection blocks many of the sites that serve the next stage.
- Turn on PowerShell script block logging, so if a command does run, your security team can see exactly what it did.
- Use a managed browser. Microsoft Edge for Business with SmartScreen, managed extensions and forced updates removes some of the ways people land on these pages, including fake extensions like the one behind CrashFix.
- Check your Macs are current. Apple added a "Possible malware, Paste blocked" alert to Terminal in macOS 26.4 for people who don't normally use Terminal and paste a command from a website or message.
- If you run a WordPress site, keep plugins and themes patched and remove the ones you don't use. The ACSC's 2026 advisory was about Australian business websites being used to attack other people's staff.
None of this relies on people spotting the trick, which is the point.
If you think it already happened
Treat any computer where someone pasted and ran one of these commands as compromised, even if nothing visible happened. Information stealers work quietly and quickly.
- Disconnect the computer from the network and get it checked or rebuilt.
- From a different, clean device, change the person's passwords, starting with email, Microsoft 365, banking and anything saved in their browser.
- Revoke their Microsoft 365 sessions so stolen session cookies stop working, and check their mailbox for new forwarding or inbox rules.
- Your IT team can look at the RunMRU registry key, which keeps a history of what was typed into the Run box.
Report it through ReportCyber at cyber.gov.au or call 1300 CYBER1 (1300 292 371). If customer or staff personal information may have been taken, check whether the Notifiable Data Breaches scheme applies.
Where Geidi fits
Our cyber security services are aligned to the Essential Eight and backed by a 24/7 security operations centre. If you'd like to talk about protecting your staff from ClickFix, talk to us.
Sources
- Microsoft Security Blog: Think before you Click(Fix): Analyzing the ClickFix social engineering technique (21 August 2025)
- Microsoft Security Blog: New ClickFix variant CrashFix deploying Python remote access trojan (5 February 2026)
- Microsoft Security Blog: From open lures to cloaked gates: how a macOS ClickFix campaign learned to hide (5 August 2026)
- ASD's ACSC: ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure (7 May 2026)
- CISA: #StopRansomware: Interlock (AA25-203A, 22 July 2025)
- mr.d0x: FileFix, a ClickFix alternative (23 June 2025)
- Check Point Research: FileFix, the new social engineering attack building on ClickFix, tested in the wild
- Microsoft Learn: Attack surface reduction rules reference
- Apple Support: If your Mac blocks a Terminal command paste or script

