ClickFix Social Engineering: When the User Becomes the Attack Vector

  • MAY 8TH, 2026
  • 2min read
ClickFix Social Engineering: When the User Becomes the Attack Vector

ClickFix is a fast-growing social engineering technique where threat actors trick users into copying and pasting malicious commands into the Windows Run dialogue, PowerShell, Terminal and macOS Terminal. Victims are shown fake CAPTCHA checks, browser verification prompts, update notices, or document errors that instruct them to fix the issue manually.

This method is highly effective because the user launches the command themselves, allowing attackers to bypass many traditional email filters, browser protections, and endpoint detections.

How it works

The attacker directs the victim to a malicious or compromised webpage through phishing emails, ads, or infected sites. The page shows a fake CAPTCHA, browser update, or document error while secretly copying a malicious command to the clipboard.

The victim is instructed to press Win + R, open PowerShell (Windows), Terminal (macOS), or Terminal/Shell (Linux), then paste and run the command.

Once run, the command can download malware, steal credentials, establish persistence, or give the attacker remote access to the system.

How to Protect Your Organisation

1. Block Suspicious Clipboard Access: Use browser policies to restrict or prompt for clipboard write access on untrusted websites.

2. Employee Awareness: Teach users to recognise fake CAPTCHA, browser update, and verification prompts. Legitimate websites should never ask users to open Run, PowerShell, or Terminal (on Windows or macOS) or execute pasted commands.

3. Restrict PowerShell (Windows) / Shell Execution (macOS/Linux): Enable Script Block Logging, enforce signed-script execution policies where applicable, and monitor for encoded or obfuscated commands. On macOS and Linux, monitor shell execution patterns and restrict unnecessary privilege escalation via sudo.

4. Endpoint Protection: Enable attack surface reduction rules and web protection to block obfuscated scripts, untrusted executables, and scripts launching downloaded malware.

Explore more CIL Advisories

Supply Chain Attacks: Compromise through Developer Tooling

Supply Chain Attacks: Compromise through Developer Tooling

Modern cyberattacks are increasingly targeting the software development ecosystem itself. Rather than attacking production servers directly, threat actors now compromise…

MAY 25TH, 2026

Read More
Defence Against Deepfake Social Engineering (BEC 2.0)

Defence Against Deepfake Social Engineering (BEC 2.0)

The days of relying on simple voice or video for identity verification are over. "Business Email Compromise" (BEC) has rapidly…

MAY 20TH, 2026

Read More
Mitigation of API Logic Abuse & Predatory Bots

Mitigation of API Logic Abuse & Predatory Bots

Traditional security tools like Firewalls and WAFs are unable to stop "Logic Abuse" because they are designed to only block…

MAY 18TH, 2026

Read More

Never miss a CIL Security Advisory

Stay informed with the latest security updates and insights from CIL.

ClickFix Social Engineering: When the User Becomes the Attack Vector

Contact Us

Message Sent!

Thank you for reaching out. We have received your message and will get back to you shortly.

Check your email for a confirmation from us.

Start a project

Project Request Submitted!

Thank you for your interest. Our team will review your project details and reach out to you soon.

Check your email for a confirmation from us.