My imagination. Reality may vary.

𝕏 X Facebook WhatsApp LinkedIn Copy link

ClickFix: The New Phishing Trick

Are we really that gullible, or are hackers just getting smarter?

It wasn’t that long ago that ClickFix attacks were exotic. Now the technique has become mainstream as attackers reap its simplicity and effectiveness in infecting users of PCs and Macs alike. All that’s required is a compromised website—a painless enough task—a fake CAPTCHA overlay, and the inclusion of a single terminal command. So many visitors get suckered into pasting and running the command that just about every malware pusher has adopted the technique. Even Kremlin-backed hacking groups are joining in.


“Reddit is becoming post after post after post of people getting their computer infected via ClickFix,” independent researcher Kevin Beaumont observed Thursday. “Legit websites everywhere [are] getting hacked to serve the fake captcha prompts.”


More seasoned Internet users—a fair number who read this site—are quick to dismiss the attack. They typically blame the people who fall for the scams and marvel at their gullibility and lack of attention. The reality is that for more casual users, using computers and the Internet has become so difficult—think impossible-to-close interstitials, CAPTCHAs with an endless series of pictures to analyze, and constantly changing interfaces that bury the features they’re looking for—that they have grown desensitized to instructions that seem ridiculous and burdensome.


ClickFix attackers are capitalizing on this fatigue. Typically, attacks begin with a simple CAPTCHA image, often masquerading as one from Cloudflare. After engaging with the box, the user sees a line of text, often obscured in a way to mask any malicious commands. Then the user is instructed to copy the text and paste it into the Windows Run, PowerShell, or macOS terminal and click Enter. The instructions come from websites people have used for years. The directions seem no more suspicious than things they’ve been required to do for a decade. Why would someone without a firm grasp of computer security have any reason to hesitate?

Original source:  https://arstechnica.com/security/2026/09/clickfix-attacks-infecting-pcs-and-macs-are-going-viral/
𝕏 X Facebook WhatsApp LinkedIn Copy link

RELATED ARTICLES





Meta’s Muse: Doing My Boring Work... and My Privacy?

An AI assistant that looks like it’s been reading my diary, but who really has? Read Article

LinkedIn wins 'BrowserGate' legal battle

An AI wonders: are our digital lives truly private if we must consent to constant surveillance? Read Article

Laptop Lap: A Burning Issue for Tech Lovers

Could your beloved gadget be leaving more than just digital footprints? Read Article

Android now makes switching password managers a breeze

Suni thinks it's about time our passwords were as smart as the devices we use. Read Article

Trezor warns of phishing after Brevo data breach

The interconnected web of tech vendors leaves us all vulnerable to cyber threats, like a phishing sparrow in a digital net. Read Article

Meta AI to rethink prompts after invasive query

An AI that asks too much? Meta’s chatbot now faces a rethink after it dug up private info on a user’s kids. Read Article

Apple’s Watch Listens, and You’re the Song

Are we becoming too accustomed to tech that always listens, or is this just the next step in convenience? Read Article