CTM360 Logo

ClickFix Attacks Expand Across Trusted Platforms

ClickFix attacks are turning a routine habit — following instructions on a computer screen — into a way for cybercriminals to gain access to victim systems.

A new report from CTM360, ClickFix & Beyond: Mapping the Expanding Family of User-Assisted Malware Delivery Techniques, examines how the social engineering technique has evolved from deceptive website prompts into a broader malware delivery method.

Instead of exploiting a software vulnerability, ClickFix convinces the victim to execute the malicious command. Attackers commonly disguise their instructions as a CAPTCHA, verification page, Cloudflare prompt, browser error, or system alert.

The victim may then receive instructions to copy a command, open the Windows Run dialog, terminal, or PowerShell, paste the command, and execute it.

That small difference is important. The attacker does not need to break through a software vulnerability when they can persuade the user to open the door themselves.

ClickFix Attacks Move Beyond Malicious Websites

Researchers first observed ClickFix in late 2023, according to CTM360, while Proofpoint formally documented the technique in 2024.

Since then, attackers have adopted ClickFix attacks at scale.

The technique has also moved beyond malicious or compromised websites. CTM360 found attackers abusing widely used platforms, including GitHub and Google Meet, to host or deliver ClickFix lures.

Using familiar services can make an attack appear more credible to a potential victim. A person may be more willing to follow instructions when the page, platform, or workflow looks like something they already trust.

Attackers are also using malicious advertising and SEO poisoning to increase distribution. These techniques can push victims toward fraudulent pages through advertisements, direct traffic, or search engine results.

The wider report demonstrates how convincing these pages can become. For example, CTM360 documents fake Cloudflare and Google reCAPTCHA overlays that instruct victims to press Win+R, Ctrl+V, and Enter. In one example, attackers disguise the malicious text as a “Cloudflare ID.” Another places the same technique over a government benefits portal.

ClickFix Attacks Target More Than Windows

The threat is not limited to Windows.

CTM360 says ClickFix attacks now target Windows, macOS, and Linux, giving the technique cross-platform reach.

ClickFix also has a relatively low technical barrier. Attackers do not need an exploit to make the technique work. Instead, they need to convince someone to perform the required actions.

This user-assisted execution creates another security problem.

Many traditional security controls focus on identifying malicious code delivered directly by an attacker. With ClickFix, the victim carries out part of the execution chain.

As a result, CTM360 says the technique can bypass some endpoint and email security controls that focus on attacker-delivered code rather than actions initiated by the user.

CTM360 Maps ClickFix From Campaign To Compromised System

CTM360 divides its analysis into two areas.

The first examines ClickFix at the campaign level. Researchers assess how attackers distribute the technique, which platforms and lures they abuse, and how the supporting infrastructure continues to evolve.

The second examines ClickFix at the host level. This part follows the execution chain and looks at what happens on a system after a victim carries out the malicious command.

Together, the two perspectives show why defending against ClickFix requires more than blocking a malicious domain or teaching employees not to click suspicious links.

The person targeted by the attack may reach the lure through search results, advertising, a compromised website, or a trusted online service. They may then receive instructions that appear to solve a legitimate technical or verification problem.

In reality, those instructions make the victim an active part of the attack chain.

CTM360 says its findings aim to help organizations improve detection, user awareness, and incident response priorities as ClickFix continues to develop as a threat vector.

Read The Full ClickFix & Beyond Report

The full 61-page CTM360 report, ClickFix & Beyond: Mapping the Expanding Family of User-Assisted Malware Delivery Techniques, provides the campaign-level and host-level technical analysis behind these findings.

[Read the full CTM360 report here]

About CTM360

CTM360 provides cyber threat intelligence focused on Indicators of Exposure (IoE), Indicators of Warning (IoW), and Indicators of Attack (IoA).

Its platform combines Cyber Threat Intelligence, External AttackRead the full CTM360 report here Surface Management, Digital Risk Protection, Third-Party Risk Management, Security Ratings, and Email Intelligence. CTM360 says its approach aims to help security teams identify exposed assets, changing risks, and emerging threats before compromise.

Shopping Cart0

Cart

Login