Backdoor.ClickFix – The Fake Verification Trap
- AUGUST 31ST, 2026
- 2min read
Hackers are increasingly exploiting human trust through a clever social engineering technique known as “ClickFix” (or “Pastejacking”). They trick Microsoft and Android users into hacking their own systems by executing malicious commands disguised as routine security checks— e.g. “I am not a robot” CAPTCHA prompts or fake browser error fixes.
What is the Vulnerability
1. The Exploit Mechanism: Victims visit a compromised site with a fake verification popup. Clicking “Verify” copies a malicious command to their clipboard (“pastejacking”). The site then prompts them to open Windows Run (Win+R), paste (Ctrl+V), and run the command to prove they are human.
2. The Vulnerability: This attack evades web security filters by manipulating users into manually running malicious commands through Windows administrative tools like PowerShell or mshta.exe.
3. The Threat: Executing the pasted command causes Windows to download and install a malicious MSI file containing a stealthy Remote Access Trojan (RAT). This results in:
4. Persistent Remote Access: Threat actors obtain an invisible, permanent backdoor into the compromised computer with full remote execution rights.
5. Credential Theft and Data Exfiltration: The Trojan can log keystrokes, harvest saved passwords, steal session cookies, and copy sensitive corporate files.
6. Ransomware and Lateral Movement: Attackers can leverage the compromised host to move laterally, deploy ransomware, or create a malicious proxy.
How to Safeguard Your Organisation
1. User Awareness & Behavioural Rule (Critical): Educate employees that no legitimate website, browser update, or CAPTCHA check will ever ask a user to press Win+R, open a terminal, or paste commands into their computer.
2. Attack Surface Reduction (ASR) & Least Privilege: Enforce Windows User Account Control (UAC) and implement Attack Surface Reduction (ASR) rules to prevent browsers or user-level processes from launching administrative utilities like PowerShell, cmd.exe, or mshta.exe.
3. Deploy EDR & Web Filtering Controls: Utilise Endpoint Detection and Response (EDR) solutions (such as TrendMicro) to flag anomalous process executions (such as commands spawned from the Windows Run registry key) and use DNS/Web filtering to block access to unverified file-sharing domains and suspicious script locations.
Explore more CIL Advisories
Defence Against Living-off-the-Cloud (LotC) & Trusted Infrastructure Abuse
Threat actors are abandoning easily blocked, newly registered domains in favour of hosting their Command and Control (C2) servers and…
AUGUST 24TH, 2026
Read More
Active Exploitation Alert: SharePoint Authentication Bypass
A critical authentication bypass vulnerability in Microsoft SharePoint Server is now under active exploitation following the public release of technical…
AUGUST 19TH, 2026
Read More
AI-Powered Vulnerability Management: Exploits Faster Than Patches
Artificial intelligence is fundamentally changing how organisations identify, prioritise, and remediate vulnerabilities. Anthropic’s Project Glasswing has shown that advanced AI…
AUGUST 17TH, 2026
Read MoreNever miss a CIL Security Advisory
Stay informed with the latest security updates and insights from CIL.