06/12/2026
We’re seeing an increase in a new social engineering attack being referred to as “ClickFix.” It’s simple, effective, and catching users off guard.
How it works: Attackers present a fake error message, CAPTCHA, or “fix this issue” prompt on a website or pop-up. Instead of doing anything technical themselves, they trick YOU into running the attack.
You may see instructions like:
- “Press Windows + R”
- “Paste this command”
- “Run this to fix your browser/connection”
If you follow these steps, you could unknowingly install malware, ransomware, or give attackers direct access to your system.
What to watch for:
- Unexpected pop-ups saying your device is “infected” or “broken”
- CAPTCHA or verification screens asking you to run commands
- ANY website asking you to copy/paste into Run, PowerShell, or Terminal
- Urgent language like “Fix Now” or “Immediate Action Required”
What to do instead:
1. DO NOT copy/paste or run unknown commands - ever
2. Close the browser or window immediately
3. Report to your SPEROS IT team
4. When in doubt, assume it’s malicious
If you or your team has already interacted with something like this, or even if you’re unsure, contact SPEROS immediately. The sooner we look, the faster we can contain and protect your environment.