Cybersecurity researchers from Insikt Group have identified a rapidly growing threat known as the ClickFix campaign.
This attack uses deceptivesocial engineering tactics to trick both Windows and macOS users into manually running malicious commands on their own computers.
Fake Alerts and Hidden Commands
Since May 2024, experts have tracked five distinct clusters of this campaign. Instead of relying on complex software flaws, hackers are using fake human-verification checks and error messages to trap victims.
When a user encounters one of these fake pages, they are manipulated into copying a hidden piece of code.
The page then provides instructions telling the victim to open built-in system programs, such as the Windows Run dialog box, PowerShell, or the macOS Terminal, and paste the code.

Because these commands are executed through trusted, built-in system tools, the attack is considered a “living-off-the-land” technique.
By tricking the user into running the code themselves, the hackers completely bypass normal web browser security and standard antivirus checks.
Once pasted, the script runs silently in the computer’s memory and downloads dangerous software, such as password stealers or remote access trojans.
Because the malicious files are never saved directly to the hard drive, they leave very few traces for security software to find.

Defending Against The Threat
Experts predict that ClickFix will remain a primary method for hackers to break into systems throughout 2026.
As these attacks become more advanced, the fake alerts are expected to become even more convincing, automatically adjusting their appearance based on the victim’s location or operating system.

According to Recorded Future research, security teams can no longer rely solely on blocking known malicious websites. Instead, administrators must aggressively restrict access to the system tools that ClickFix abuses.
In Windows environments, this means using Group Policy Objects (GPOs) to turn off the Windows Run dialog box and restrict how PowerShell scripts can execute.
For macOS systems, administrators should limit access to the Terminal application. Finally, organizations must train their employees to recognize these attacks.
Users need to understand that legitimate websites will never ask them to copy and paste strange codes into system tools to fix an error or verify their identity.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.