What Is ClickFix?
ClickFix is a social-engineering technique that has exploded in popularity because it sidesteps almost every traditional malware defense. Instead of tricking you into downloading and running an executable file — something antivirus software and browser download warnings are specifically built to catch — ClickFix tricks you into typing (or pasting) and running a command yourself, using tools that are already built into your operating system.
How the Attack Works
You land on a compromised or malicious website, and instead of a normal page, you see what looks like a CAPTCHA or "verification required" screen. Instead of a checkbox or an image challenge, it instructs you to:
- Press Windows key + R to open the Run dialog (or open Terminal on a Mac)
- Press Ctrl+V (or Cmd+V) to paste something — the page has already silently copied a malicious command to your clipboard using JavaScript
- Press Enter to "complete verification"
Because you are the one who executes the command, no file was ever "downloaded" in the way antivirus tools expect to catch. The command itself often uses built-in tools like PowerShell, mshta, or certutil to quietly fetch and install malware in the background, sometimes while displaying a fake "verification successful" message to keep you from suspecting anything.
Why It's So Effective
Most people have been trained for years to distrust email attachments and suspicious downloads, but almost nobody has been warned specifically about being told to paste a command into a Run dialog. The instructions are also often dressed up convincingly, referencing familiar-sounding brands or claiming to be a routine anti-bot check that dozens of legitimate sites use every day.
The Single Most Important Rule
No legitimate CAPTCHA or human-verification system — not Google reCAPTCHA, not hCaptcha, not Cloudflare Turnstile — has ever, under any circumstance, asked a user to open a terminal, a Run dialog, or PowerShell and paste something. Real human-verification is either a simple checkbox, an image-selection puzzle, or an invisible background check. If a "verification" step asks you to touch a command line, it is not a CAPTCHA — it is malware installation disguised as one.
Other Red Flags to Watch For
- Mentions of PowerShell, mshta, certutil, curl, or "iex" (Invoke-Expression) in the visible instructions
- Claims that a code or "fix" has already been copied to your clipboard for you
- Urgency language pushing you to "verify now" before continuing
- The page appears after visiting a torrent site, a cracked-software download, or a suspicious ad redirect
What to Do If You Already Ran the Command
If you followed instructions like this and pressed Enter, act quickly: disconnect the device from the internet (Wi-Fi and Ethernet), run a full scan with reputable anti-malware software, and change your important passwords from a separate, clean device — not the potentially infected one. Consider a full OS reinstall if you handle sensitive data on that machine.
Staying Safe Going Forward
Treat any pop-up or webpage instructing you to open a terminal, Run dialog, or command prompt as an automatic red flag, regardless of how official it looks. When in doubt, paste the exact instructions into a checker before acting on them — never run a command you don't fully understand just because a website told you to.
Frequently Asked Questions
ClickFix is a fake 'verification' or CAPTCHA screen that tricks you into opening the Run dialog, PowerShell, or Terminal, pasting a malicious command already copied to your clipboard, and pressing Enter — installing malware that you technically ran yourself.
No. Real human-verification systems like Google reCAPTCHA, hCaptcha, and Cloudflare Turnstile only ever use a checkbox or an image-selection challenge. Any instruction to open a terminal or paste a command is never a legitimate CAPTCHA.
Yes — the ClickFix Fake-CAPTCHA Malware Detector scores any pasted instructions against known ClickFix patterns like Run-dialog prompts, clipboard-paste-and-execute requests, and false 'prove you're human' claims. It's a one-time $5.49 purchase — no subscription, no account required.
Disconnect from the internet, run a full anti-malware scan, and change your important passwords from a different, clean device as soon as possible.
No — for your safety, it only analyzes the wording of the instructions you paste. It never executes any code, so it's safe to paste suspicious text into it without any risk to your device.