ClickFix Trick: “Not a Robot” to Run Commands

The Hacker News · Medium sophistication
Last updated September 1, 2026

The article describes a real-world social engineering technique called ClickFix that Microsoft observed frequently: a fake “prove you’re not a robot” page silently copies a command to the user’s clipboard and then instructs them to paste it into a terminal. Because the user runs the command themselves and no attachment is delivered, it can bypass many traditional security checks and becomes easy for attackers to repeat at scale.

Key findings

  • ClickFix uses a fake “prove you are not a robot” webpage to get users to paste a pre-copied command into a terminal.
  • Microsoft observed ClickFix as a dominant initial access method in its notifications (reported as 47%).
  • Bitdefender reports many high-severity incidents rely on “living off the land” (using built-in tools already present on systems) rather than installing obvious malware.
  • The article argues attackers prioritize repeatable playbooks over “clever” one-off attacks, enabling high-volume operations.

Who’s being targeted

  • Commonly targeted roles: All employees, Executive team, IT helpdesk / support, Security operations (SOC/MDR consumers).
  • Affected industries: Cross-industry (any organization with end users and web access).
  • Attack channels: website.
  • Impersonated: A generic website verification/CAPTCHA page.

Awareness takeaways

  • Train employees: a real CAPTCHA will never ask you to open a terminal or paste commands, stop and report immediately.
  • Reinforce “don’t run what you don’t understand”: pasting commands from a webpage is equivalent to installing software.
  • Focus defenses on repeatable attacker playbooks (not just ‘advanced’ malware): reduce what can run and who can run it.
  • Don’t rely on detection alone, ensure alerts are actively monitored and acted on.

Red flags to watch for

  • A CAPTCHA/verification step instructs you to open Terminal/Command Prompt (unusual for normal web browsing).
  • Instructions require pasting and running a command you did not type or understand.
  • The page manipulates your clipboard without clear consent or business reason.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You land on a site and it says, “Prove you’re not a robot.” Looks normal, right? This one isn’t. This ClickFix trick quietly copies a command to your clipboard, then walks you through: open Terminal or Command Prompt, paste, and run it yourself. Here’s the catch: real CAPTCHAs never tell you to open a terminal. If a web page wants you to paste a command you didn’t type or understand, that’s game over, stop right there. If any ‘not a robot’ page tells you to open Terminal or Command Prompt, close it and report it to IT Security immediately.

Similar attacks

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Fake GitHub “ClickFix” Spreads macOS AmnesiaStealer

Researchers say a real macOS malware campaign is using “ClickFix” social engineering to trick users into installing an infostealer called AmnesiaStealer. Victims are lured to a counterfeit GitHub download page that encourages them to copy/paste a Terminal command, which then downloads and runs the…

August 14, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake GitHub Page Tricks Mac Users Into Malware

Fake GitHub Page Tricks Mac Users Into Malware

Researchers found a real macOS malware campaign that uses a fake GitHub download page to convince users to paste a command into Terminal and enter their Mac password. The malware then steals credentials, cookies, and files, and can even turn the victim’s Chromium browser into a remotely controlled…

August 17, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026