ClickFix persuades a person to copy, paste or run a command under the cover of a routine verification or technical fix.
A human-operated malware delivery technique
ClickFix is a social-engineering pattern, not a single malware family. A page claims that something is broken or that the visitor must prove they are human, then presents unusual keyboard or command-running instructions. The visitor is manipulated into starting the infection themselves.
Common warning signs
- A CAPTCHA asks for Windows Run, Terminal, PowerShell or another system tool.
- The page asks you to paste something you cannot clearly inspect.
- A verification step includes multiple keyboard shortcuts.
- The page uses urgency, a browser error or a document problem to justify the action.
Why ordinary scanning may miss it
The page may reveal the lure only after a click or delay, serve different content by device, or retrieve instructions from another service. URL Radar therefore separates static evidence, rendered behaviour and coverage limits instead of claiming that one response proves the site is safe.
What to do
Do not follow the instructions. Close the page and report the URL. If a command was already run, treat the device as potentially compromised and contact the appropriate security team.
Reference: Microsoft Threat Intelligence’s ClickFix analysis.