
ClickFix Lures Trick Users Into Pasting Commands
ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…
Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning password changes alone may not be enough and token revocation is required.
Microsoft documented two separate intrusion chains that both rely on the same core trick, known as ClickFix. Victims land on a fake page, often after clicking a malicious ad or a search result manipulated through SEO tactics, and are told to copy a command and paste it into the Windows Run box to resolve a supposed issue. One documented case involved a page impersonating Anthropic's Claude AI assistant, reached through malicious Google ads.
Once the victim pastes the command and presses Enter, the infection begins. One chain is largely fileless and can hide payload data inside a JPEG downloaded from an image-hosting service. The other pulls a DLL from a remote WebDAV share using a disguised filename, then persists through a hidden scheduled task made to look like a routine software update.
The attack does not rely on any software vulnerability. As the reporting notes, neither chain exploits a vulnerability; it only runs because a person read a prompt and pressed Enter. This makes the technique effective against well-patched systems, since the weak point is human trust rather than a technical flaw. Malvertising and SEO manipulation also help the lure reach users who are actively searching for legitimate tools, making the fake page feel like a normal result rather than an unsolicited message.
Organizations and individuals can reduce risk from this style of attack with a few consistent habits:
Because the malware targets Microsoft 365 documents and synced OneDrive and SharePoint files in addition to browser credentials, security teams should pair user awareness training with monitoring for unusual scheduled tasks and token activity across cross-industry Microsoft 365 environments.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
A ClickFix attack is a social engineering trick where a fake webpage or prompt instructs a user to copy a command and paste it into Windows Run to fix a supposed problem, which instead executes malware.
According to Microsoft's findings, ACR Stealer collects saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders.
Because the malware can steal live session tokens in addition to passwords, Microsoft advises revoking tokens rather than only rotating passwords.
The prompts arrive through malvertising or SEO-manipulated search results, including a page impersonating Anthropic's Claude reached through malicious Google ads.
You search for Claude, click a top Google result, and a "ClickFix" box pops up: copy this command into Windows Run to continue. The moment you paste and hit Enter, ACR Stealer installs. It quietly grabs saved browser passwords, live Microsoft 365 tokens, and files from OneDrive and SharePoint, no exploit, just you following that prompt. Big red flag: real sites like Claude or Microsoft 365 never tell you to open Win+R and paste a mystery command. That ClickFix box is just social engineering dressed up as tech support. If any website tells you to paste a command into Windows Run or Terminal, stop. Close it, and report it to security immediately before you press Enter.

ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…

Researchers reported a real phishing campaign (“Operation BlueDash”) that tricks users with a “secure document” lure and routes them to a fake Microsoft Store…

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Attackers abused Anthropic’s Claude “Artifacts” publishing feature to host a convincing fake Claude download page on the real claude.ai domain. Victims found…

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools…