ClickFix is one of 2026's fastest-growing malware tricks. It doesn't ask you to download anything — it tricks you into infecting your own device, one click at a time.
Here's exactly what one of these fake pages looks like. Click the checkbox like a real visitor would:
Clicking the box doesn't run a real check — it silently copies a hidden command to your clipboard.
The page then tells you to press Win + R, then Ctrl + V, then Enter — "to complete verification."
That pastes and runs a PowerShell command that downloads real malware — password stealers, crypto wallet stealers, or remote-access tools — onto your computer.
No file was ever downloaded, no antivirus warning triggered before this point. You did it yourself, one click and one paste at a time.
No real CAPTCHA, browser update, or "fix" ever asks you to open Run or Terminal and paste something. If a page ever tells you to do that — no matter how official it looks — close it. That instruction is the entire scam.
The trick is brilliantly simple: a fake CAPTCHA, “verify you’re human” popup, or error message instructs the victim to copy a command and paste it into the Windows Run box, a terminal, or the browser console. The victim does the attacker’s job for them — and because they typed it themselves, many security prompts never trigger. Fake comments on YouTube and hijacked search ads did the rest.
Nothing about the page looks malicious. It mimics trusted brands, uses real CAPTCHA designs, and creates a mild sense of urgency (“verify within 30 seconds”). The instructions feel technical enough to be legitimate and simple enough to follow. Understanding that no real website will ever ask you to paste commands into your computer is the single rule that defeats this entire category.
Most malware has to sneak past a browser, an email filter and an antivirus product. ClickFix skips all of that by persuading you to run the malicious command yourself, using tools already built into your own computer. Nothing is downloaded that a filter could inspect, so nothing gets blocked.
It has spread quickly since it emerged, because it works on careful people. The victim is not tricked into clicking something suspicious. They are guided, politely and in clear steps, into performing an action that looks like routine troubleshooting.
What is typically installed is an information stealer: it takes saved browser passwords, session cookies, autofill data and cryptocurrency wallets, and sends them off within seconds. Stolen session cookies are especially damaging because they can let an attacker into accounts without needing your password or your two-factor code.
No legitimate website will ever ask you to paste a command into your computer's Run box, PowerShell, or Terminal. Not to view a document. Not to prove you are human. Not to fix a display problem. Not ever.
Real verification steps happen inside the web page: click a checkbox, pick the squares with traffic lights, drag a slider. They never leave the browser. The moment a website's instructions involve the Windows key and R, or opening Terminal, or pressing Ctrl+V into a black window, you are being attacked. Close the tab.
The attack borrows the language of legitimate technical support. The instructions are calm, numbered and specific. They arrive at a moment of mild frustration, when something already appears broken, and they offer to end that frustration. And the command is usually hidden behind clipboard trickery, so you paste a long line you never really read.
It also exploits the fact that many people have, at some point, been told by genuine support staff to run a command. The pattern feels familiar. The difference is that a real support agent you called is not the same as a web page you stumbled onto.
Keep your browser and operating system updated. Do not store passwords in the browser itself — use a dedicated password manager, which is far harder for a stealer to extract. Turn on two-factor authentication, ideally passkeys, so a stolen password alone gets nobody in. And share the rule above with the people you help with technology, because it is simple, absolute, and easy to remember.
A scam that shows you a fake error or verification failure and then talks you through pasting a malicious command into your own computer, so the malware is run by you rather than downloaded past your security software.
Any website asking you to press Windows+R, open PowerShell or open Terminal and paste something is an attack. Legitimate verification never leaves the browser window.
Probably not. These payloads are designed to run silently and often delete themselves afterwards. Treat the device as compromised, change your passwords from a different device, and sign out of all sessions everywhere.
Not reliably. Because you run the command yourself using built-in system tools, there is no suspicious download for a filter to catch. Some security products detect the follow-on activity, but you should not count on it.
These attacks steal session cookies, which are the tokens that keep you logged in. With a stolen cookie an attacker can enter an account without your password or your two-factor code. Signing out everywhere invalidates them.