Live Threat Pulse: 2,847 threats detected in last 24h

menu_book Tactic

ClickFix

Also known as: Click Fix, Fake CAPTCHA attack

ClickFix is a social-engineering technique that tricks users into running a malicious command themselves — typically via a fake CAPTCHA or error page instructing them to paste text into the Windows Run dialog or terminal. It has become a major delivery method for infostealers like LummaC2.

What is ClickFix?

ClickFix presents a victim with a fake verification or error message ("verify you are human", "fix this error") that instructs them to copy a provided command and paste it into the Windows Run dialog (Win+R) or a terminal. Running it downloads and executes malware — the user effectively infects their own machine.

Why ClickFix works

It bypasses many automated defences because the user, not an exploit, executes the payload. The fake CAPTCHA framing exploits user familiarity with verification prompts, making the instruction feel routine.

How VantaPrism Tracks ClickFix

ClickFix is a leading delivery route for modern stealers; VantaPrism captures the resulting stolen data, helping defenders quantify exposure from these self-inflicted infections.

Check Your Exposure arrow_forward

Frequently Asked Questions

Why is ClickFix hard to block?

expand_more
The victim runs the malicious command themselves rather than an exploit triggering it, so it sidesteps many automated protections that watch for exploit behaviour.

What does a ClickFix attack look like?

expand_more
A fake CAPTCHA or error page tells the user to paste a command into the Run dialog or terminal to "verify" or "fix" something; running it installs malware.
← All Glossary Terms Last reviewed: June 2026