Jump to content

ClickFix

From Wikipedia, the free encyclopedia

ClickFix is a social engineering technique. It typically shows a popup over a webpage instructing the viewer to run a system command that will install malware.[1][2]

The first ClickFix version was discovered in October 2023.[3]

Research from Hudson Rock showed that ClickFix often forms a feedback loop, using credentials stolen by infostealers to compromise administrative accounts on legitimate websites and host new ClickFix lures.[4] In July 2026, researchers detailed an incident where stolen WordPress credentials led to a ClickFix campaign on an Artlist subdomain using Polygon smart contracts (EtherHiding) for dynamic payload routing.[5]

In March 2026, Apple added a mitigation to macOS to prevent ClickFix style attacks.[6][7] In April, a modified variant using the applescript:// URI scheme to bypass the use of the Terminal application was found.[8]

See also

[edit source]

Further reading

[edit source]
  • "Think before you Click(Fix): Analyzing the ClickFix social engineering technique". Microsoft Security Blog.

References

[edit source]
  1. Fadilpašić, Sead (2025-11-07). "Experts warn ClickFix malware attacks are back, and more dangerous than ever before - here's how to stay safe". TechRadar. Retrieved 2026-04-09.
  2. Goodin, Dan (2025-11-11). "ClickFix may be the biggest security threat your family has never heard of". Ars Technica. Retrieved 2026-04-09.
  3. Fermo, Vincent; Gsas '26 (2025-10-15). "ClickFix: How Hackers Use 'Verification' to Steal Your Information". Fordham University Information Security and Assurance. Retrieved 2026-04-10.{{cite web}}: CS1 maint: numeric names: authors list (link)
  4. "From Victim to Vector: How Infostealers Turn Legitimate Businesses into Malware Hosts". Hudson Rock. 2025-12-30. Retrieved 2026-07-31.
  5. "How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist". InfoStealers. 2026-07-14. Retrieved 2026-07-31.
  6. Toulas, Bill. "Apple adds macOS Terminal warning to block ClickFix attacks". BleepingComputer. Retrieved 2026-04-09.
  7. "I put Apple's new macOS ClickFix warnings to the test and they actually worked — now I want them on Windows too". Tom's Guide. 2026-03-31. Retrieved 2026-04-09.
  8. "New ClickFix variant bypasses Apple safeguards with one‑click script execution". CSO Online. Retrieved 2026-04-09.
[edit source]