ClickFix attacks infecting PCs and Macs are going viral

| Source: Ars Technica AI

Tags: ClickFix, social engineering, BlueVoyant, cybersecurity, malware, Windows, macOS, nation-state threats

ClickFix attacks trick users into pasting malicious commands into Windows or macOS terminals via fake CAPTCHA overlays on compromised websites. Now mainstream and adopted by Kremlin-linked groups, the technique eliminates code-signing requirements entirely — any hacked website becomes a mass-infection vector with no malware infrastructure needed.

Details

ClickFix has evolved from an obscure technique into one of the most widely adopted malware delivery methods of 2026. The attack places a fake CAPTCHA overlay on a compromised website, then instructs users to copy a hidden malicious command into Windows Run, PowerShell, or a macOS terminal — delivering malware without any download prompt or file execution. Security firm BlueVoyant, tracking associated malware as Lorem Ipsum, documented the pivot to ClickFix in late May 2026. Previously, attackers needed signed Microsoft Installer packages, SEO-manipulated download portals, and rotating delivery domains. ClickFix eliminates all of that — the user running the command becomes the delivery mechanism, replacing technical legitimacy with social legitimacy. Independent researcher Kevin Beaumont reports Reddit is now flooded with infected-machine posts. The technique has attracted Kremlin-linked hacking groups, signaling its low cost and broad victim pool make it viable for nation-state operations, not just cybercrime gangs. The root driver is UX fatigue: users conditioned by years of arbitrary digital friction — pop-up gauntlets, endless CAPTCHAs, constantly moving interfaces — no longer question unusual online instructions. Enterprise security training must now explicitly cover terminal command social engineering alongside email phishing.