Cybercriminals have found a clever workaround for modern security tools: convince the user to run the malware for them. This technique, known as ClickFix, has surged in popularity, with Microsoft reporting campaigns targeting thousands of enterprise and consumer devices every single day. At FusionTek, our security stack detected and blocked this threat for our customers before any damage was done.
In this post, we break down how ClickFix works, why it bypasses traditional defenses, and how our managed security services keep your organization protected.
What Is ClickFix?
ClickFix is a social engineering technique that manipulates users into copying and running malicious commands on their own computers. Rather than exploiting a software vulnerability, attackers exploit human psychology — specifically, our natural tendency to follow step-by-step instructions to “fix” a seemingly minor technical problem.
The name comes from the pattern: you click a verification button, then follow instructions for a fix, which in turn allows the running of malware.
According to Microsoft’s Threat Intelligence team, ClickFix campaigns have been active since early 2024 and have delivered some of the most prolific malware in circulation today, including Lumma Stealer, multiple remote access trojans (RATs), and sophisticated rootkits.
How the Attack Works: A Four-Stage Chain
Stage 1: The Bait — Phishing, Malvertising, or Compromised Sites
Attackers deliver the initial lure through three primary channels:
- Phishing emails with payment or invoice themes, often containing links that redirect through traffic distribution systems
- Malicious advertisements on streaming or free-content sites that open scam pages in new tabs
- Compromised legitimate websites (often WordPress) that briefly show real content before replacing it with the attack page
These lures frequently impersonate trusted brands — Booking.com, the Social Security Administration, Cloudflare, Google reCAPTCHA, and even Discord — to lower suspicion.
Stage 2: The Fake Verification Page
The victim lands on a page that looks like a standard human-verification check. They see messages like “Verify you are human” or “I’m not a robot — reCAPTCHA Verification ID: XXXX.”
When the user clicks the checkbox, two things happen simultaneously:
- A hidden script copies an obfuscated PowerShell command to the user’s clipboard
- The page updates with “helpful” instructions explaining how to “fix” a supposed error
Stage 3: The “Fix” — User-Executed Malware
This is the critical moment. The page instructs the user to:
- Press Win + R to open the Windows Run dialog
- Press Ctrl + V to paste
- Press Enter to run
The command is typically heavily obfuscated — using Base64 encoding, string concatenation, nested execution, and benign-sounding phrases like “Microsoft Defender Services Secure Access” to avoid detection.
Because the user initiates the execution, traditional antivirus and email security tools often don’t intercept it.
Stage 4: The Payload — Fileless Malware in Memory
Once executed, the command downloads and runs malware directly in memory, rarely writing a traditional executable file to disk. Instead, it injects into legitimate Windows processes (PowerShell, msbuild.exe, rundll32.exe) using living-off-the-land techniques.
Common payloads include:
- Infostealers (Lumma Stealer) — harvest credentials, cookies, and financial data
- Remote Access Tools (Xworm, AsyncRAT, NetSupport, SectopRAT) — enable hands-on keyboard access for lateral movement
- Loaders (Latrodectus, MintsLoader) — deliver additional malware
- Rootkits (modified r77) — establish deep, persistent access
The attack also targets macOS users with equivalent Terminal-based instructions.
Why ClickFix Bypasses Conventional Security
ClickFix is particularly insidious because it operates in a “blind spot” for many security tools:
| Defense Layer | Why ClickFix Bypasses It |
|---|---|
| Email security | Links may use legitimate redirectors (Google Ads); attachments are HTML, not executable |
| Web filtering | Pages are hosted on compromised legitimate domains with valid SSL |
| Antivirus | No malicious file is downloaded — the user runs a “trusted” system tool |
| Endpoint protection | PowerShell and Run dialog are legitimate Windows features |
That is exactly why FusionTek takes a different approach, one that watches behavior, not just files.
How FusionTek’s Security Stack Detected and Blocked It
While ClickFix is designed to evade traditional defenses, our layered security stack is built specifically to catch behavioral anomalies, even when a human initiates them. Here is how our tools identified and neutralized the threat at multiple stages of the attack chain for our customers:
Our customers were protected. The attack was detected, blocked, and remediated, with zero impact to their operations.
Catching ClickFix is not about having one magic product. It is about having a complete, managed security program that works together — monitored 24/7 by experts who know what to look for.
FusionTek’s Managed Security Services combine:
- 24/7 Security Operations Center (SOC) — Our analysts monitor alerts in real time, investigating suspicious behavior and responding to threats around the clock so you do not have to
- Advanced Endpoint Detection and Response (EDR) — Behavioral monitoring that catches fileless malware, living-off-the-land techniques, and suspicious process injection — exactly the tactics ClickFix uses
- Network and DNS Protection — Blocking malicious domains, C2 servers, and suspicious traffic patterns before they reach your environment
- Email and Web Security — Filtering phishing messages, malicious links, and compromised websites at the gateway
- Vulnerability and Gap Analysis — We do not just defend; we assess. Our gap analysis testing identifies weaknesses in your security posture and gives you a clear roadmap to strengthen it
- User Awareness Training — Because the human is the target, we help your team recognize social engineering tactics like ClickFix before they fall for them
This is not a one-time setup. Our team continuously tunes detection rules, updates threat intelligence, and adapts to new attack techniques — so when the next ClickFix variant appears, we are already ready.
What Every Organization Should Do Now
Based on Microsoft’s recommendations and our own defense experience, here are practical steps to strengthen your posture:
Educate Your Users
- Train staff to recognize fake CAPTCHA and verification pages
- Emphasize: never copy and paste commands from a website into your computer
- Teach users what the Windows Run dialog is and why unknown instructions to use it are suspicious
Harden Your Environment
- Disable the Run dialog (Win+R) via Group Policy for users who do not need it
- Enable PowerShell script block logging and set execution policies to AllSigned or RemoteSigned
- Configure Windows Terminal to warn when pasting multi-line text
- Deploy application control policies that prevent native binaries from launching via Run
Strengthen Your Technical Defenses
- Enable network and web protection to block malicious domains
- Turn on cloud-delivered antivirus protection for rapid threat updates
- Use attack surface reduction rules to block obfuscated script execution
- Monitor RunMRU registry entries for suspicious command patterns
Assess Your Gaps
- Conduct a security gap analysis to understand where your current defenses fall short
- Review your incident response plan for social engineering scenarios
- Test your detection capabilities with simulated attack exercises
Not Sure Where Your Gaps Are? We Can Help
ClickFix proves that even well-equipped organizations can be vulnerable if they lack layered, behavior-based detection and continuous monitoring. Many businesses think they are protected, until an attack like this reveals the gaps.
FusionTek offers security gap analysis testing to help organizations understand their current security posture, identify blind spots, and build a roadmap for stronger protection. Whether you are a small business with basic antivirus or an enterprise with a partial security stack, we can show you exactly where ClickFix could slip through.
Ready to strengthen your defenses? Contact us today to schedule your gap analysis and learn how our Managed Security Services can protect your organization 24/7.
The Bottom Line
ClickFix represents a shift in cyberattack strategy: instead of breaking through technical defenses, attackers are breaking through human ones. The good news is that with the right combination of behavioral detection, network protection, expert monitoring, and user awareness, these attacks can be caught and stopped — before they ever reach your data.
At FusionTek, that is exactly what we do. Our security stack detected this threat, our analysts responded, and our customers stayed safe. That is the power of managed security done right.




