FREE TOOL · CLICKFIX SCAM EXPLAINER

"Verify You're Human" — Or Are You Installing Malware?

ClickFix is one of 2026's fastest-growing malware tricks. It doesn't ask you to download anything — it tricks you into infecting your own device, one click at a time.

Here's exactly what one of these fake pages looks like. Click the checkbox like a real visitor would:

!
Verify you are human
Ray ID: 8f3a2c91d0e4 · cloudflare.com
1

Clicking the box doesn't run a real check — it silently copies a hidden command to your clipboard.

2

The page then tells you to press Win + R, then Ctrl + V, then Enter — "to complete verification."

3

That pastes and runs a PowerShell command that downloads real malware — password stealers, crypto wallet stealers, or remote-access tools — onto your computer.

4

No file was ever downloaded, no antivirus warning triggered before this point. You did it yourself, one click and one paste at a time.

Quick check: what should you actually do?

Follow the instructions — it looks official
Close the tab immediately, don't press anything it tells you to
Try it once to see what happens, you can undo it after
THE ONE RULE THAT MATTERS

No real CAPTCHA, browser update, or "fix" ever asks you to open Run or Terminal and paste something. If a page ever tells you to do that — no matter how official it looks — close it. That instruction is the entire scam.

How ClickFix Spread So Fast

The trick is brilliantly simple: a fake CAPTCHA, “verify you’re human” popup, or error message instructs the victim to copy a command and paste it into the Windows Run box, a terminal, or the browser console. The victim does the attacker’s job for them — and because they typed it themselves, many security prompts never trigger. Fake comments on YouTube and hijacked search ads did the rest.

Why Smart People Fall For It

Nothing about the page looks malicious. It mimics trusted brands, uses real CAPTCHA designs, and creates a mild sense of urgency (“verify within 30 seconds”). The instructions feel technical enough to be legitimate and simple enough to follow. Understanding that no real website will ever ask you to paste commands into your computer is the single rule that defeats this entire category.

If You Already Pasted Something

The attack that asks you to infect yourself

Most malware has to sneak past a browser, an email filter and an antivirus product. ClickFix skips all of that by persuading you to run the malicious command yourself, using tools already built into your own computer. Nothing is downloaded that a filter could inspect, so nothing gets blocked.

It has spread quickly since it emerged, because it works on careful people. The victim is not tricked into clicking something suspicious. They are guided, politely and in clear steps, into performing an action that looks like routine troubleshooting.

How it plays out

  1. You land on a page — through a search result, a compromised legitimate site, an advert, or a link in a message.
  2. Something appears broken. A fake verification box that will not complete, an error saying a font or driver is missing, a document that will not display, a "confirm you are human" step that fails.
  3. The page offers a fix, with numbered instructions: press these two keys, then paste, then press Enter. Often it has already copied the command to your clipboard for you.
  4. Following those steps opens a system tool — the Run dialog or PowerShell on Windows, Terminal on a Mac — and executes a command that downloads and runs malware.
  5. The page then shows a success message, so nothing feels wrong. The infection is already done.

What is typically installed is an information stealer: it takes saved browser passwords, session cookies, autofill data and cryptocurrency wallets, and sends them off within seconds. Stolen session cookies are especially damaging because they can let an attacker into accounts without needing your password or your two-factor code.

The rule that stops it completely

No legitimate website will ever ask you to paste a command into your computer's Run box, PowerShell, or Terminal. Not to view a document. Not to prove you are human. Not to fix a display problem. Not ever.

Real verification steps happen inside the web page: click a checkbox, pick the squares with traffic lights, drag a slider. They never leave the browser. The moment a website's instructions involve the Windows key and R, or opening Terminal, or pressing Ctrl+V into a black window, you are being attacked. Close the tab.

Why it is convincing

The attack borrows the language of legitimate technical support. The instructions are calm, numbered and specific. They arrive at a moment of mild frustration, when something already appears broken, and they offer to end that frustration. And the command is usually hidden behind clipboard trickery, so you paste a long line you never really read.

It also exploits the fact that many people have, at some point, been told by genuine support staff to run a command. The pattern feels familiar. The difference is that a real support agent you called is not the same as a web page you stumbled onto.

If you already ran the command

  1. Disconnect the device from the internet to cut off the data being sent out.
  2. From a different, clean device, change the passwords on your email first, then banking, then everything important. Doing it from the infected machine just hands over the new passwords.
  3. Sign out of all sessions everywhere on your major accounts. Most services have this option in their security settings. This is essential because stolen cookies allow access without a password.
  4. Run a full scan with reputable security software. Understand that stealers often delete themselves after running, so a clean scan does not prove nothing happened.
  5. Consider a full reinstall of the operating system if anything valuable was on that machine. It is the only way to be certain.
  6. Watch your accounts closely for the next few months and report any fraud to your bank promptly.

Reducing the risk in advance

Keep your browser and operating system updated. Do not store passwords in the browser itself — use a dedicated password manager, which is far harder for a stealer to extract. Turn on two-factor authentication, ideally passkeys, so a stolen password alone gets nobody in. And share the rule above with the people you help with technology, because it is simple, absolute, and easy to remember.


Frequently asked questions

What is ClickFix in one sentence?

A scam that shows you a fake error or verification failure and then talks you through pasting a malicious command into your own computer, so the malware is run by you rather than downloaded past your security software.

How do I recognise it instantly?

Any website asking you to press Windows+R, open PowerShell or open Terminal and paste something is an attack. Legitimate verification never leaves the browser window.

I pasted the command but nothing happened. Am I safe?

Probably not. These payloads are designed to run silently and often delete themselves afterwards. Treat the device as compromised, change your passwords from a different device, and sign out of all sessions everywhere.

Does antivirus stop it?

Not reliably. Because you run the command yourself using built-in system tools, there is no suspicious download for a filter to catch. Some security products detect the follow-on activity, but you should not count on it.

Why does signing out of all sessions matter so much?

These attacks steal session cookies, which are the tokens that keep you logged in. With a stolen cookie an attacker can enter an account without your password or your two-factor code. Signing out everywhere invalidates them.