Dashboard

What Is a ClickFix Attack? How the Paste Trick Works

A ClickFix attack tricks you into running a malicious command yourself. How the fake CAPTCHA works, why builders are exposed, and a four-question test.

Cecilia Iona
Cecilia Iona
Senior Editor, AI & Product
2 October 20261 min read

A ClickFix attack is a social engineering technique that tricks you into running a malicious command yourself. A web page shows a fake verification or error message, silently copies a command to your clipboard, then tells you to paste and run it. No exploit is needed, because you do the attacker's work for them, which is why it slips past many defenses.

Microsoft's October 2026 Digital Defense Report says ClickFix-style commands executed on more than 1.1 million unique devices between February and early May 2026, roughly an eightfold increase. We summarized the wider report in what the Microsoft Digital Defense Report means for builders.

How a ClickFix attack works

Microsoft's analysis of the technique describes four steps:

  1. The lure. You land on a page that looks like a verification step. Microsoft lists fake reCAPTCHA and Cloudflare Turnstile screens, spoofed Discord and banking pages, and impersonated government agencies as common disguises.

  2. The silent copy. When you click "verify" or "fix", the page copies an obfuscated command to your clipboard without telling you.

  3. The instruction. You are told to open the Windows Run dialog with Win+R, or a terminal or PowerShell window, and paste. In Microsoft's words, the technique "typically gives the users instructions that involve clicking prompts and copying, pasting, and running commands directly in the Windows Run dialog box, Windows Terminal, or Windows PowerShell."

  4. The payload. The pasted command downloads and runs malware.

Microsoft reports that infostealers are the typical result, naming LummaStealer as the most prolific final payload it observed. Other payloads include remote access tools such as Xworm and AsyncRAT, loaders, and rootkits.

Why it works

Most phishing asks you to click a link or open a file, and security tools are tuned to catch both. ClickFix asks you to type a command into your own computer. The browser did nothing wrong, the download never touched a mail filter, and the action was taken by a logged-in human.

The trick also leans on a believable story. A CAPTCHA that does not load, a document that "needs a fix", a meeting link that "requires an update". Each one makes the extra step feel like routine troubleshooting.

Why builders are a good target

If you build with AI tools, pasting commands is a normal part of the day. A tutorial says to run an install command. An AI assistant gives you a one-liner to fix a build error. A forum answer says to paste this into your terminal. Each time, a command from somewhere else runs with your permissions, on a machine that probably holds API keys, cloud logins, and source code.

That is the habit ClickFix exploits. We have no evidence in the sources above that builders are singled out, only that the technique depends on people running commands they did not write and do not fully read. Builders do that more often than most.

The consequences are also larger for a builder. An infostealer on a developer laptop can collect saved browser passwords, session cookies, and tokens, which is the kind of credential compromise that Microsoft's report counts in 20% of observed initial access.

A four-question test before you paste anything

  1. Did I ask for this command? If a website volunteered it, stop. A real CAPTCHA never asks you to open a terminal or the Run dialog.

  2. Do I know what every part does? If you cannot explain it, do not run it. Ask an AI assistant to explain the command line by line, but do that in a separate tab, not by pasting the mystery text into an agent with shell access.

  3. Is it obfuscated? Long strings of encoded text, or commands that download and run something in one line, are the pattern Microsoft describes. Legitimate install steps are usually short and readable.

  4. Does the source belong to the thing it claims to be? The command should come from the official documentation of the tool, reached by typing the address yourself, not from a pop-up.

If you already ran something you now doubt, disconnect from the network, change passwords and revoke tokens from a different, clean device, and run a malware scan. The credentials your machine held are the thing to protect first.

What defenders do

For organizations, Microsoft's recommendations include educating users on social engineering, enabling SmartScreen and network and web protection, disabling the Run dialog through Group Policy where it is not needed, and turning on PowerShell script block logging. For a solo builder, the equivalent is the test above plus turning on two-factor authentication, so a stolen password alone is not enough, and keeping an eye on what AI coding tools install on your behalf. The wider catalog of risks is in AI risks: a practical guide for builders.

FAQ

What does ClickFix mean?

It is the name for attacks that present a fake problem and a fake "fix" which is really a command for the victim to run. The victim executes the malicious step themselves.

Is ClickFix only a Windows problem?

Microsoft's analysis describes Windows prompts, specifically the Run dialog, Windows Terminal, and PowerShell. The underlying idea, persuading someone to paste a command, is not tied to one operating system.

How do I tell a real CAPTCHA from a fake one?

A real CAPTCHA works inside the page. It never tells you to press keyboard shortcuts, open a terminal, or paste anything.

Can antivirus stop ClickFix?

Sometimes, but the attack is built to avoid the usual triggers, because the victim runs the command. Awareness and layered controls matter more than any one tool.

How did this land?

About the author

Cecilia Iona
Cecilia Iona

Senior Editor, AI & Product

Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.

Share

Get the next post in your inbox

One email a month. Product updates, engineering posts, and the best of Built with Swarmz.

I agree to receive emails about AI building tips and Swarmz product news. Unsubscribe any time.