ClickFix attacks, which rely on compromised websites, fake CAPTCHA overlays, and a single terminal command, have become a dominant infection vector for malware. According to a report by Ars Technica, the technique has been widely adopted by cybercriminals and state-sponsored hacking groups alike.
“Reddit is becoming post after post after post of people getting their computer infected via ClickFix,” independent researcher Kevin Beaumont said in a social media post on Thursday. “Legit websites everywhere [are] getting hacked to serve the fake captcha prompts.”
The attack works by tricking users into copying and pasting a malicious terminal command, often disguised as a security verification step. More experienced internet users often dismiss the scams as obvious, but the report notes that for casual users, the constant barrage of CAPTCHAs, pop-ups, and confusing interfaces has desensitised them to such prompts.
The technique, once considered exotic, has now become a staple in the malware ecosystem, with attackers finding it relatively easy to compromise legitimate websites and inject the fake overlays.