Security guides

What Is ClickFix?

Understand the ClickFix social-engineering technique, its fake verification prompts and the warning signs defenders can detect.

ClickFix persuades a person to copy, paste or run a command under the cover of a routine verification or technical fix.

A human-operated malware delivery technique

ClickFix is a social-engineering pattern, not a single malware family. A page claims that something is broken or that the visitor must prove they are human, then presents unusual keyboard or command-running instructions. The visitor is manipulated into starting the infection themselves.

Fake problem→Copy instruction→Open a system tool→Run concealed content

Common warning signs

Why ordinary scanning may miss it

The page may reveal the lure only after a click or delay, serve different content by device, or retrieve instructions from another service. URL Radar therefore separates static evidence, rendered behaviour and coverage limits instead of claiming that one response proves the site is safe.

What to do

Do not follow the instructions. Close the page and report the URL. If a command was already run, treat the device as potentially compromised and contact the appropriate security team.

Reference: Microsoft Threat Intelligence’s ClickFix analysis.

Continue learning

Explore the detection catalogue.

Browse detectionsCheck a link