ClickFix attacks, which use fake CAPTCHA overlays to trick users into pasting malicious commands into their system terminals, have gone mainstream and are now infecting both PCs and Macs. The technique has been widely adopted by various threat actors, including Kremlin-backed hacking groups, as attackers exploit user fatigue with increasingly burdensome CAPTCHA experiences on the internet.
Background
ClickFix is a social engineering technique that emerged as a low-barrier, high-effectiveness malware delivery method by exploiting the ubiquity of CAPTCHA challenges on the web. As websites increasingly rely on services like Cloudflare for bot protection, attackers hijack the familiar CAPTCHA UI to disguise malicious commands.
- Source
- Ars Technica
- Published
- Sep 11, 2026 at 07:30 PM
- Score
- 8.0 / 10