ClickFix Attacks Spreading Across Windows and Mac Devices

Follow on LinkedIn

A social engineering technique known as ClickFix is spreading rapidly and infecting both Windows PCs and Macs.

Attackers place fake CAPTCHA screens, often designed to look like Cloudflare or Google verification prompts, on compromised websites. When users interact with the fake check, a malicious command is quietly copied to their clipboard. The page then instructs them to paste the text into the Windows Run dialog, PowerShell, Windows Terminal, or the Mac Terminal and press Enter.

Once the command runs, it can download and install malware. Common payloads include information-stealing tools that grab passwords, browser data, and cryptocurrency wallet information, as well as remote access tools that give attackers control of the device.

Security researchers say the method has moved from a niche tactic to a mainstream one in 2026. Compromised legitimate websites, including smaller business and content sites, are frequently used to host the fake verification pages. Variants such as TerminalFix direct users specifically to Windows Terminal or PowerShell so longer scripts can run more easily. Some campaigns have also targeted Mac users with similar Terminal prompts.

Microsoft and other firms have documented campaigns that go beyond simple stealers. In some cases, the malware establishes reverse tunnels that can give attackers a path into an organization’s internal network. Researchers have also noted large numbers of compromised sites involved in these attacks.

Experts stress that real CAPTCHA or human-verification checks never ask users to open a terminal or paste a system command. Anyone who sees such instructions should close the page immediately and avoid running the command.

Users can reduce risk by keeping software updated, being cautious on unfamiliar or suddenly suspicious sites, and treating any request to run terminal commands from a web page as a red flag. Organizations are advised to monitor for unusual PowerShell or Terminal activity and limit access where possible.

Reference links

Related Posts

Leave a Reply

Your email address will not be published. Required fields are marked *

×