ClickFix scams are a form of social engineering that trick people into performing actions that can expose their computers to malware. Instead of simply asking victims to download a suspicious file, scammers may use fake CAPTCHA tests, browser errors, security alerts, or software-update messages to persuade users to copy and run commands.
The technique has become a significant cybersecurity concern. Microsoft has reported ClickFix campaigns targeting Windows and macOS devices, while Switzerland’s National Cyber Security Centre reported in August 2026 that more than 100,000 websites worldwide had been affected by compromised websites using fake CAPTCHA-style attacks.
What Is a ClickFix Scam?
ClickFix is a social-engineering technique designed to make a malicious action appear like a legitimate troubleshooting or verification step.
For example, you might visit a website and see a message claiming:
- “Verify that you are human.”
- “Your browser needs to be updated.”
- “An error occurred while loading this page.”
- “Follow these steps to continue.”
- “Copy and paste the verification command.”
The page may then instruct you to use keyboard shortcuts, open Windows Run, PowerShell, Command Prompt, or Terminal, and paste something into the window.
This is where the danger begins.
Microsoft explains that ClickFix attacks commonly rely on victims copying, pasting, and executing malicious commands themselves. These campaigns can ultimately lead to information theft and malware infections.
Important: A legitimate CAPTCHA should not require you to execute an unknown command on your computer.
How ClickFix Attacks Work
A ClickFix scam commonly follows a sequence like this:
- You visit a malicious, compromised, or deceptive website.
- A fake CAPTCHA, browser error, or security message appears.
- The page tells you that an additional verification or repair step is necessary.
- You are instructed to copy something or use a keyboard shortcut.
- You are encouraged to paste the content into a system utility.
- The command may download or launch unwanted software.
- The malware may attempt to steal information or compromise the device.
Microsoft has documented ClickFix campaigns delivered through phishing, malicious advertising, and compromised websites.
Why Are ClickFix Scams Dangerous?
ClickFix attacks take advantage of something that makes traditional cybersecurity defenses more difficult: the victim is persuaded to participate in the attack.
Rather than automatically exploiting a vulnerability, the scam attempts to convince the user that they are fixing a technical problem.
The Center for Internet Security describes ClickFix as a social-engineering technique that can be used to distribute malware and facilitate data or financial theft.
This is why cybersecurity awareness is particularly important.
Common Signs of a ClickFix Scam
1. A CAPTCHA Tells You to Open Windows Run
Be suspicious if a CAPTCHA or verification page instructs you to press Windows + R.
Windows Run is a legitimate operating-system feature, but a random website should not be asking you to use it to complete a CAPTCHA.
2. You Are Asked to Paste a Command
One of the strongest warning signs is being told to copy and paste text into:
- Windows Run
- PowerShell
- Command Prompt
- Windows Terminal
- macOS Terminal
If you don’t understand what the command does, don’t run it.
The University of Oregon specifically warns users to stop if a CAPTCHA or pop-up asks them to use keyboard commands, copy and paste text, or open Terminal or Windows Run.
3. A Fake Browser Error Appears
Some ClickFix campaigns imitate browser crashes or technical errors.
Others may make a page look like a legitimate service is experiencing a temporary problem.
The goal is to make the visitor believe that following the displayed instructions is necessary to continue.
4. The Page Looks Like a Familiar Security Service
ClickFix campaigns have been observed impersonating familiar services and verification systems.
Microsoft has documented examples involving fake reCAPTCHA and Cloudflare Turnstile-style pages, as well as pages impersonating other legitimate services.
A familiar-looking logo does not prove that the page is genuine.
5. The Page Creates a Sense of Urgency
Be cautious when a website tells you:
- “Act now.”
- “Verification required.”
- “Your browser is outdated.”
- “Fix the problem immediately.”
- “Complete this step to continue.”
Scammers often use urgency to discourage users from investigating.
Where Can ClickFix Scams Appear?
ClickFix attacks can be delivered through several channels, including:
Compromised Websites
A legitimate website may be compromised and modified so that visitors are redirected to a malicious verification page.
Malicious Advertisements
Some users may encounter ClickFix pages after interacting with deceptive advertisements or redirects.
Phishing Emails
Attackers can send emails containing links that lead to fake verification pages.
Search Results
Malicious or compromised websites can sometimes appear through search-related traffic, making it important to verify websites before following unusual instructions.
Fake Software Updates
A page may claim that your browser, media player, or another application needs an immediate update.
Instead of clicking the suspicious prompt, open the software’s official website or built-in update feature.
Are ClickFix Scams Only a Windows Problem?
No.
ClickFix has also been used against macOS users.
Microsoft has documented campaigns that attempted to trick Mac users into executing commands associated with malware such as Atomic macOS Stealer.
Therefore, both Windows and Mac users should be cautious when a website asks them to execute unfamiliar commands.
How to Protect Yourself From ClickFix Scams
Never Execute Unknown Commands
This is the most important precaution.
If an unfamiliar website tells you to copy and paste a command into your computer, stop and verify the instructions before doing anything.
Don’t Trust a CAPTCHA That Requires Command-Line Instructions
A normal CAPTCHA is designed to distinguish humans from automated systems.
It should not require you to execute a command in Windows Run, PowerShell, Command Prompt, or Terminal.
Close Suspicious Pages
If a webpage suddenly displays a strange security warning or fake verification process, close the browser tab.
You do not need to follow the instructions simply because the page claims that you must.
Keep Your Browser and Operating System Updated
Install updates through your device’s normal update mechanism or the software developer’s official website.
Avoid downloading updates from unexpected pop-ups.
Use Reputable Security Software
Keep your device’s built-in security protections enabled and ensure your security software is up to date.
For Windows users, you can learn more about Microsoft’s security protection through the official Microsoft Security website.
Be Careful With Online Advertisements
Avoid clicking suspicious advertisements, particularly when they redirect you through several unexpected pages.
If an advertisement suddenly claims your device has a serious problem, close the page rather than calling a number or installing software from the pop-up.
What Should You Do If You Already Followed a ClickFix Scam?
If you already copied and executed a command from a suspicious website, don’t panic, but take the situation seriously.
1. Stop Using the Suspicious Website
Close the browser tab and avoid interacting with the page again.
2. Disconnect the Device if You Suspect Malware
If you believe malicious software may have been installed, disconnecting the device from the internet can help limit unwanted communication while you investigate.
3. Run a Security Scan
Use your trusted security software to perform a thorough scan.
Windows users can consult the official Microsoft Defender information page for guidance on Windows security features.
4. Change Important Passwords
If you suspect that credentials may have been exposed, change important passwords from a trusted device.
Prioritize your email, financial, shopping, social-media, and other important accounts.
5. Enable Multi-Factor Authentication
Where available, turn on multi-factor authentication for important accounts.
This provides an additional security layer even if a password is compromised.
6. Monitor Your Accounts
Watch for unfamiliar login notifications, password-reset messages, purchases, or other unusual activity.
If you notice suspicious financial transactions, contact your bank or financial institution through its official contact channels.
7. Get Professional Help if Necessary
If malware is detected or your device continues behaving unusually, consider contacting a qualified computer-security professional.
ClickFix Scams vs. Traditional Phishing
| Feature | Traditional Phishing | ClickFix |
|---|---|---|
| Main tactic | Deceptive message or website | Social engineering |
| Common lure | Fake login, attachment, or link | Fake CAPTCHA, error, or update |
| Victim action | Click, download, or enter information | Copy, paste, and execute |
| Potential risk | Credential theft or malware | Malware, information theft, or unauthorized access |
| Human interaction | Important | Central to the attack |
ClickFix can also be combined with phishing, malicious advertising, and compromised websites.
How to Tell a Real CAPTCHA From a ClickFix Scam
A legitimate CAPTCHA normally asks you to complete a verification challenge within the webpage.
A suspicious ClickFix-style CAPTCHA may instead ask you to:
- Press Windows + R.
- Open PowerShell.
- Open Command Prompt.
- Open Terminal.
- Copy and paste text.
- Run a command.
- Download an unfamiliar program.
- Disable security software.
If the “CAPTCHA” requires any of these actions, leave the page.
Frequently Asked Questions
Is ClickFix a virus?
No. ClickFix is a social-engineering technique rather than a specific virus. Attackers use it to persuade people to execute commands that may download or launch malware.
Can a fake CAPTCHA infect my computer?
A fake CAPTCHA itself may simply be a webpage, but following its instructions can result in malicious commands being executed and malware being downloaded.
Does pressing Windows + R automatically infect my computer?
No. Simply opening Windows Run does not automatically mean that your computer has been infected. The major risk comes from following the scam’s instructions and executing an unknown command.
Can ClickFix affect Mac computers?
Yes. Security researchers have documented ClickFix campaigns targeting macOS as well as Windows.
Can ClickFix steal passwords?
Depending on the malware delivered, attackers may attempt to steal browser credentials, cookies, financial information, cryptocurrency-wallet information, or other sensitive data.
What should I do if a CAPTCHA tells me to copy and paste a command?
Do not do it. Close the page and access the website or service through its official website or application.
Final Thoughts
ClickFix scams show how cybercriminals increasingly rely on social engineering rather than simply exploiting technical vulnerabilities.
The safest approach is to slow down whenever a website suddenly asks you to perform an unusual action.
A CAPTCHA should not require you to open PowerShell, Windows Run, Command Prompt, or Terminal and execute an unknown command.
If a webpage tells you to copy, paste, run, or execute something to “fix” a problem, stop and verify it first.
Useful Cybersecurity Resources
For additional information and security guidance, readers can consult:
- Microsoft Security — Security news, threat intelligence, and protection guidance.
- Microsoft Security Support — Security and scam-protection guidance.
- Center for Internet Security — Cybersecurity information and best practices.
- Swiss National Cyber Security Centre — Cybersecurity alerts and guidance.
- University of Oregon ClickFix guidance — Practical information about fake CAPTCHA and ClickFix attacks.
Related Security Guides
- How to Remove Mairozisha.com Pop-ups.
- Bitcat Airdrop Review
- Lunei.shop Review
- How to Remove Shopbyte6.xyz Pop-ups and Notifications
- How to Remove Diteringion.com Pop-ups
- Fake CAPTCHA Scams
- AI-Powered Scam Websites
- Fake Crypto Giveaway Scams
- Smishing Scams
- Fake Tech Support Pop-Ups
- Malicious Browser Notifications
