ClickFix attacks infect PCs and Macs in viral wave

ClickFix attacks exploit user trust to bypass security, spreading malware across Windows and macOS in a viral wave.

By Central
Highlights
  • ClickFix attacks trick users into copying and pasting malicious commands into their terminal.
  • The technique bypasses traditional security controls by making the user execute the command locally.
  • Security firms warn that ClickFix represents a fundamental shift in malware distribution methods.

The cybersecurity landscape has a new dominant strain of infection, and it is spreading with alarming speed across both Windows PCs and macOS systems. Known as ClickFix, this attack methodology has triggered what multiple security firms are now calling a viral wave, marking a fundamental shift in how malware is distributed. Unlike the exploit-driven attacks of the past that relied on technical vulnerabilities, ClickFix weaponizes a far simpler vector: the user’s own willingness to follow instructions. By tricking individuals into copying and pasting malicious commands directly into their own terminal or PowerShell window, attackers have bypassed many of the traditional defenses that operating system vendors have spent years building. The result is a cross-platform crisis that is forcing a re-evaluation of endpoint security, user education, and the very definition of a “voluntary” action in cybersecurity.

The Mechanics of ClickFix: How a Simple Copy-Paste Breaks Decades of Security

At its core, a ClickFix attack is deceptively straightforward. A user visits a compromised website, often served through malvertising, SEO-poisoned search results, or legitimate sites that have been injected with malicious code. The user sees a fake browser error, a CAPTCHA prompt, or a message claiming their browser is out of date. The instruction is always the same: press a keyboard shortcut to copy a command, then open a terminal or run dialog and paste it. What the user does not realize is that this command downloads and executes malware, often infostealers, remote access trojans, or cryptominers.

The brilliance of this technique, from an attacker’s perspective, lies in its circumvention of almost every modern security control. Email gateways, web filters, and endpoint detection systems are built to flag files, scripts, and executables that arrive through standard channels. But a user typing a command into their own terminal is, from the operating system’s perspective, a legitimate local action. The malware never visibly travels over the wire as a suspicious attachment; it is summoned by the user themselves. This social engineering layer is what makes ClickFix so difficult to stop with technology alone. The operating system trusts the user, and the user trusts the screen in front of them.

For the attackers behind the Lorem Ipsum malware campaign, tracked by security firm BlueVoyant, this new approach has been transformative. Prior to adopting ClickFix, these threat actors relied on a resource-intensive infrastructure stack that included SEO-manipulated download portals, malvertised landing pages, Microsoft-trusted code-signing certificates, and a constantly rotated network of domains serving Microsoft Installer packages. The pivot to ClickFix in late May 2026 eliminated the code-signing requirement entirely. BlueVoyant noted that the new model substitutes the legitimacy of a validly signed installer with a different form of legitimacy: a user voluntarily executing the malicious command in their own terminal. That single shift broadened the victim pool from users specifically searching for pirated software or meeting tools like Microsoft Teams to virtually anyone browsing a compromised website.

Why ClickFix Represents a Strategic Evolution in Malware Delivery

To understand why ClickFix is spreading like a viral wave, it is necessary to look at the economics of cybercrime. For years, attackers faced an escalating arms race with operating system vendors. Apple and Microsoft hardened their platforms, enforced stricter code-signing rules, and deployed technologies like Gatekeeper, SmartScreen, and app reputation systems. Buying valid code-signing certificates became expensive, and those certificates were frequently revoked once security researchers flagged them. Maintaining the server infrastructure for traditional drive-by downloads required constant investment in domain rotation, hosting, and SEO manipulation.

ClickFix changes this calculus entirely. The attack infrastructure required to run a ClickFix campaign is dramatically cheaper and simpler than what was needed for traditional malware delivery. There is no need to compile and sign executables for every new variant. There is no need to register hundreds of domains to stay ahead of blocklists. The attacker simply needs a compromised website and a payload URL. The user does the rest. This democratization of malware distribution means that groups with smaller budgets, including state-sponsored actors and low-level cybercriminals, can now achieve the same infection rates as well-resourced advanced persistent threat groups.

The data supports this assessment. Security firm Netskope recently identified a ClickFix campaign that was beaconing back to more than 5,400 compromised websites. That number is an indicator of the campaign’s reach and scope, and it represents only one of many concurrent ClickFix operations active today. When multiplied across the dozens of groups that have adopted this technique, the total attack surface is staggering. The viral wave is not an accident of a single campaign; it is the natural result of a delivery mechanism that offers the highest return on investment of any malware distribution method currently available.

The macOS Problem: Bypassing Gatekeeper with a Single Command

While ClickFix attacks work on Windows, the situation for macOS users is in many ways more troubling. Apple’s Gatekeeper is designed to prevent users from running unsigned or notarized software. It has been a relatively effective defense against traditional malware delivery. But ClickFix renders Gatekeeper almost irrelevant. Mac security firm Jamf and an independent researcher, Bugra Sahinoglu, have independently documented macOS variants of ClickFix that bypass Gatekeeper protections entirely. The mechanism is identical to the Windows version: the user is tricked into running a terminal command that downloads and executes malware, but on macOS, the attacker can also request user permissions for Accessibility, Input Monitoring, or Full Disk Access during the terminal session, further deepening the compromise.

One of the documented macOS payloads is tracked as MacSync Stealer, a code-signed Swift-based malware that has evolved specifically to exploit the ClickFix delivery model. Because the user voluntarily launches the binary from the terminal, macOS does not flag it the same way it would a program downloaded from the internet, which would trigger quarantine attributes and Gatekeeper checks. The malware arrives as a seemingly innocuous script that, once executed, installs persistence mechanisms and begins exfiltrating data. The ClickFix model has effectively turned the terminal, a tool designed for power users, into the primary attack surface on both platforms.

ClickFix Attackers Are Weaponizing Public Services and Blockchain Infrastructure

The adaptability of ClickFix attackers is one of the most concerning aspects of this trend. Security researchers are consistently finding new ways that threat actors are integrating legitimate public services into their ClickFix chains. Cisco Talos documented attackers using publicly published Google Sheets documents as part of the ClickFix delivery chain. By hosting malicious commands or configuration data inside a Google Sheet, attackers gain a layer of legitimacy and persistence. The traffic to Google servers does not look suspicious to network monitors, and the attacker can update the content of the sheet at any time without touching their own infrastructure.

Even more sophisticated actors are taking this concept further. Russia’s state-sponsored Sandworm group, known for disruptive attacks against critical infrastructure, has been observed hosting command-and-control infrastructure inside blockchain-based smart contracts. This approach makes takedown efforts extraordinarily difficult. Traditional C2 servers can be seized, sinkholed, or blocked by internet service providers. A smart contract on a decentralized blockchain cannot be removed by any central authority. The commands sent to infected machines are read from the blockchain, making the attack infrastructure resilient to law enforcement and private-sector disruption. Security firm Netskope confirmed that other campaigns are now replicating this method, indicating that the bar for infrastructure complexity is shifting downward while the sophistication of persistence is shifting upward.

The TerminalFix Variant: Microsoft Documents the Next Evolution

Microsoft’s security team recently documented a related campaign it calls TerminalFix, which represents a further evolution of the ClickFix model. In this variant, the attack uses a multistage intrusion process that deploys reverse tunnels through the victim’s system. Rather than simply downloading a binary, TerminalFix establishes a persistent reverse shell that tunnels out through protocols commonly allowed by corporate firewalls, such as HTTPS or DNS. The attacker can then move laterally within the network, deploy additional payloads, and maintain access even if the initial infection vector is cleaned up. TerminalFix demonstrates that ClickFix is not a static technique; it is a platform that attackers are actively improving. Each documented variant adds new layers of stealth, persistence, and operational security.

What Is ClickFix and How Does It Work? A Direct Technical Explanation

ClickFix is a social engineering attack method in which a user is deceived into copying a malicious command from a web page and pasting it into their operating system’s command-line terminal, resulting in the execution of malware. The infection chain begins when a user lands on a compromised or malicious website. The page displays a fake error message or a false CAPTCHA challenge that instructs the user to press a specific keyboard combination, such as Ctrl+C on Windows or Command+C on macOS, to copy a hidden command. The user is then directed to open a terminal window, a Run dialog, or a Spotlight search bar and press Ctrl+V or Command+V to paste and execute the command. The command typically downloads and runs a malicious payload from a remote server without triggering standard antivirus or security software, because the execution is initiated locally by the user. This technique bypasses web filters, code-signing checks, email gateways, and operating system protections like Apple’s Gatekeeper or Microsoft’s SmartScreen, which are designed to block files arriving from the internet but cannot distinguish between a user typing a legitimate command and a user typing a malicious one.

Why Victim Blaming Makes the ClickFix Crisis Worse

One of the most dangerous narratives emerging around ClickFix is the tendency to blame victims for falling for these attacks. The assumption is that only technically naive users would copy and paste a command into their terminal without understanding what it does. This framing is not only unhelpful but actively harmful to security outcomes. ClickFix attacks are increasingly sophisticated in their presentation. The fake CAPTCHA prompts and error messages are visually identical to legitimate ones. The web pages hosting them are often legitimate sites that have been injected with malicious code, so the user has no reason to suspect they are being attacked. Even seasoned IT professionals have been observed falling for these attacks in controlled testing environments, because the psychological pressure of a simulated browser error triggers a reflexive compliance response.

The broader point, emphasized by the researchers who track these campaigns, is that victim-blaming and shaming only make the problem worse. When users are afraid to report that they may have been compromised, detection and response times lengthen. The attacker gains more time to move laterally, exfiltrate data, and establish persistence. The most effective countermeasure to ClickFix is not to assume it will only happen to less experienced users, but to build systematic defenses and foster a culture of reporting without stigma. Every organization should assume that some percentage of their users will eventually encounter a ClickFix prompt, and the question is whether the organization has prepared its people and its technology to respond.

Tools and Defenses That Can Blunt ClickFix Attacks Today

Despite the effectiveness of ClickFix, there is a growing ecosystem of defenses designed to detect and block these attacks at the moment of execution. One of the most notable tools for macOS is BlockBlock, developed by the security researcher Patrick Wardle. BlockBlock monitors the system for processes that attempt to establish persistence, and it can intercept a ClickFix attack the moment the user presses the paste keystroke combination. By analyzing the command before it executes, BlockBlock can identify known malicious patterns, download URLs, and script behaviors. Similar functionality has been integrated into the uBlock Origin content blocker, which can now block the fake CAPTCHA pages and error overlays before the user ever sees them. On the Windows side, Microsoft’s SmartScreen and Defender have been updated to monitor for suspicious command-line activity, and enterprise endpoint detection and response platforms from CrowdStrike, SentinelOne, and others have developed specific detections for the ClickFix execution pattern.

However, no single tool is a silver bullet. The attackers are actively testing their payloads against these defenses and modifying their commands to evade detection. They frequently obfuscate the download URLs, use legitimate cloud storage services to host binaries, and chain multiple commands to make each individual step look innocuous. The arms race is accelerating, and the defense side is currently playing catch-up. The most effective strategy combines technology with education. Browser-based filters can block the initial landing page. Endpoint detection can catch the execution. But the last line of defense is a user who has been trained to recognize the ClickFix pattern: a legitimate-looking prompt that asks them to copy and paste a command into a terminal.

The Human Element: Building Awareness Beyond the Security Team

For security professionals, the rise of ClickFix represents an uncomfortable shift in responsibility. The technical controls that once formed a reliable safety net are now less effective against an attack that bypasses them entirely. The burden of prevention falls, at least in part, on the individual user. This is an uncomfortable reality because it requires reaching people who have no interest in cybersecurity, no technical training, and no reason to question a website that looks normal. Those of us with more security training should build awareness with our less experienced neighbors, family members, and friends. This is not a corporate training problem; it is a community education problem. The mass adoption of ClickFix demonstrates its success, and it is not going away any time soon.

The most effective message to communicate is simple: no legitimate website, service, or software vendor will ever ask you to copy and paste a command into your terminal to fix a problem. If you see a prompt that instructs you to press Windows Key + R, or Command + Space, or to open a terminal and paste something, close the browser tab immediately. That single heuristic stops the vast majority of ClickFix attacks. For organizations, this message should be posted in Slack channels, included in security newsletters, and discussed in team meetings. It is a message that needs to reach people who do not read security blogs and who have never heard the term ClickFix. For them, the warning that legitimate websites will never ask you to run a terminal command is the difference between staying safe and becoming the next victim in this viral wave.

The Future of ClickFix: What the Next Generation of Attacks Will Look Like

Looking forward, there is every reason to believe that ClickFix will continue to evolve and spread. The economics of the attack are too favorable for the defenders to fully shut it down. As operating system vendors and security companies build new defenses, attackers will find new ways to work around them. Microsoft has already documented the TerminalFix variant, which adds reverse tunneling and multistage persistence. It is reasonable to expect future variants that leverage artificial intelligence to generate more convincing social engineering prompts, that use encrypted messaging platforms for command-and-control, or that integrate directly with browser extensions to modify the attack surface in real time. The blockchain-based infrastructure used by Sandworm and other groups will likely become standard practice, making takedowns nearly impossible.

The security industry is at a inflection point. ClickFix has demonstrated that the most sophisticated attack does not need to exploit a zero-day vulnerability or bypass a kernel-level defense. It needs only to exploit the natural human inclination to trust instructions that appear on a screen. That trust, once broken, is difficult to restore. Every user who falls for a ClickFix attack becomes less trusting of legitimate prompts, which creates its own set of usability problems for security teams who need users to respond to genuine alerts. The long-term solution will require a combination of technical controls that can detect command execution patterns, browser-level protections that prevent the initial injection, and a widespread cultural shift in how users think about the terminal. Until that shift happens, ClickFix will remain the most efficient malware distribution method available, and the viral wave shows no signs of receding.

Share This Article