Security / Privacy
The Scam Where the Victim Does the Installing
ClickFix attacks disguise malicious instructions as CAPTCHAs or troubleshooting steps and persuade victims to run the attack themselves.
#Security #Malware #Social Engineering #ClickFix #Phishing
One of the stranger attack trends of 2026 does not begin with an invisible exploit.
It begins with instructions.
TechCrunch reported on the growth of ClickFix attacks, where a malicious or compromised page presents something that looks like a CAPTCHA, security check, or technical fix and tells the visitor to copy, paste, or run commands on their own computer.
The user becomes the installer.
That is why this attack works even when the instructions look technical and authoritative.
The simple rule
A normal CAPTCHA should not require you to open a terminal, PowerShell, command prompt, Run dialog, developer console, or other system tool and paste commands into it.
Neither should a streaming site, social network, document viewer, or ordinary login page.
If a website tells you to run a command to prove you are human or fix your browser, stop.
Close the page. Do not paste the command somewhere else just to see what it does. If you already followed the instructions, disconnect from sensitive accounts until the device can be checked, and review important account sessions from a different trusted device.