
If a web page tells you to copy a command and run it to fix an error or prove you are human, treat it as suspicious. ClickFix is a social-engineering technique that persuades the user to execute an attacker’s command, often through Windows Run, PowerShell, Terminal or another trusted system tool.
Microsoft reported increased ACR Stealer activity between late April and mid June 2026. The campaigns used ClickFix lures to steal browser passwords, cookies, authentication tokens and sensitive documents. Microsoft recommends isolating affected devices, rotating exposed credentials and revoking potentially compromised tokens, so a password reset alone may not be enough.
Why ClickFix works
A typical lure resembles a CAPTCHA, browser error or document problem. The user is told to copy and run a command. That command can start a chain that downloads or executes malware.
Microsoft has also documented fake CAPTCHA and QR lures appearing across phishing campaigns. ClickFix can bypass some traditional controls because the victim launches the command rather than opening a malicious attachment. This fits the wider pattern covered in why phishing only attacks are rising.
| What you see | What you are told | What may be happening |
|---|---|---|
| Fake CAPTCHA | Complete a human check | A malicious command is prepared for execution |
| Browser or document error | Run this fix | A trusted system tool launches attacker-controlled code |
| Fake update prompt | Paste a command to continue | Malware may download, execute or steal browser data |
It is not only a Windows issue. Microsoft has documented macOS ClickFix-style campaigns using fake utility fixes, Terminal commands, AppleScript and native tools to deploy infostealers that can collect browser credentials, session data and Keychain information.
Why stolen sessions matter
A stolen session token can let an attacker reuse an authenticated session. MFA remains essential, but it does not automatically invalidate a stolen token. Incident response may therefore require token revocation and forced re-authentication as well as password changes.
Passkeys and FIDO2 are worth the effort for stronger sign-in, while knowing what to do when company credentials surface on the dark web remains important.
The Cyber Security Breaches Survey 2025/2026 found that 38% of UK businesses experienced phishing in the previous 12 months. Among businesses that experienced a breach or attack and identified the most disruptive type, 69% selected phishing.
What actually reduces the risk
- Train staff to recognise fake CAPTCHA, verification and paste-and-run instructions.
- Use application control and attack-surface reduction measures to restrict untrusted script execution.
- Monitor suspicious PowerShell, MSHTA, rundll32 and browser credential-store access.
- Make token revocation and session review part of incident response.
- Use behaviour-based endpoint detection alongside conventional antivirus.
The difference is explained in EDR compared with antivirus and XDR, supported by endpoint hardening steps that reduce real world attacks and how zero trust works with endpoint security. Running phishing simulations can test whether staff recognise these lures.
FAQs
Does ClickFix always install malware?
No. ClickFix describes the social-engineering technique, not one specific payload. Attackers can use it to deliver different scripts or malware.
Will resetting a password remove the risk?
Not necessarily. If browser sessions or authentication tokens may have been stolen, security teams should also revoke affected sessions or tokens and investigate the endpoint.
Can ClickFix affect Macs?
Yes. Microsoft has documented macOS ClickFix-style campaigns using Terminal, AppleScript and native utilities to deliver information-stealing malware.
Where to start
Brief staff on this lure through cyber security awareness training and make sure your response process can revoke sessions quickly. MDR services in London can support continuous detection, while dark web monitoring, network penetration testing, IT consulting services in London and global IT support for international projects can strengthen the wider control environment.
Call Northern Star on +44 (0) 800 319 6032 or book a callback with our London team. You can also see how we work as a managed service provider in London.












