You land on a page and get the usual little annoyance: "Verify you're human." Except instead of clicking a checkbox or picking out traffic lights, this one asks you to press Windows key + R, then Ctrl + V, then Enter. It calls itself a security check. It's actually the entire attack.

This technique has a name now — security researchers call it ClickFix — and it's become one of the most common ways ordinary people end up with malware on their computer, precisely because it doesn't look like a virus at all. It looks like a chore.

How the trick actually works

The page walks you through what looks like routine "human verification":

What actually gets pasted is a command — usually something that looks like meaningless gibberish, or a short, official-looking "verification ID" hiding the real payload further off-screen. The moment you press Enter, that command runs with your own permissions, quietly downloading and installing malware built to steal saved passwords, browser data, and account credentials.

"Only amateurs attack machines; professionals target people." — Bruce Schneier

Why this slips past antivirus software

Normally, antivirus software is watching for a suspicious file to download or an attachment to open — something it can scan. ClickFix skips that step entirely. There's no file for anything to catch, because nothing was downloaded. You did the installing yourself, using tools that are supposed to be there (Run, Terminal, PowerShell), which makes it look like ordinary user activity instead of an attack.

It's a good example of what real attacks tend to look like once you strip away the movie version: not a dramatic break-in, just a moment of trust in a routine most people click through without reading.

How to tell it's fake, and what to do

  • A real CAPTCHA never leaves your browser. Clicking images, checking a box, or typing distorted letters — that's it. If a "verification" step ever asks you to open the Run box, Terminal, or any system window, it's not a CAPTCHA.
  • Close the tab immediately. No legitimate site — not Microsoft, not your bank, not a shipping company — needs you to paste anything to prove you're human.
  • Just seeing the fake page doesn't infect you. The danger only happens if you actually paste the command and press Enter. If you're not sure, clear your clipboard and move on.
  • If you already ran it: disconnect from the internet right away to limit the damage, run a full scan with your security software, and change your important passwords from a separate, clean device — since anything typed on the infected one may already be compromised.

The whole scam runs on one moment of habit: a familiar-looking prompt, a routine most people complete without really reading it. Read the screen instead of your muscle memory, and this one falls apart before it starts.

← Back to all posts Review the red flags