There's a "prove you're human" test making the rounds that you really don't want to pass. It's called ClickFix, and it's been so effective that it graduated from petty cybercrime to the toolkit of Russia's most elite state hackers. When both groups use the same trick, that trick works.
The setup
You hit a webpage — from a search result, an ad, an emailed link — and get a familiar-looking box. Maybe a Cloudflare-style checkbox. Maybe a Google-style CAPTCHA. Maybe an error message with a helpful "fix." Then come the instructions: press Windows+R. Now Ctrl+V. Now Enter.
Here's what you can't see: the page already loaded a malicious command onto your clipboard. Windows+R opens the Run box, Ctrl+V pastes the attacker's PowerShell, Enter runs it. No download, no attachment, nothing for your antivirus to flag — you personally typed the burglar's key into your own lock. On a Mac? Same con, except they ask you to paste into Terminal.
Researchers have a name for why this works: verification fatigue. We've spent years clicking crosswalks and fire hydrants to prove our humanity. One more weird verification step just doesn't register as strange anymore.
What actually gets installed
Mostly password thieves and remote-access trojans. The big one is Lumma Stealer — Microsoft calls it the most prolific ClickFix payload — and it grabs saved browser passwords, cookies, active session tokens, crypto wallets. Campaigns have also delivered NetSupport RAT, DarkGate, AsyncRAT, and Atomic macOS Stealer for Macs. Put simply: everything your browser remembers about you, gone in under a minute.
The one rule
A real CAPTCHA never leaves the browser. Typing characters, clicking bicycle photos, checking a box — all of it happens inside the page. So the rule is absolute: any "verification" that asks you to hit keyboard shortcuts, open Run, open Terminal, or paste anything is an attack. Not sometimes. Always. No real website needs you to run a command to prove you exist.
Three habits finish the job:
- If a website put something on your clipboard and you didn't copy it yourself, it's hostile. Don't paste it.
- Never run a command you didn't write and can't explain — no matter how official the page asking looks.
- Weird pop-up "fix" or surprise verification? Close the tab. If you actually need the site, get back in through a bookmark.
Already pasted it?
Assume your passwords and logins are burned, and move fast. Disconnect the machine from the internet. From a different, clean device, change your email password first — email resets everything else — then your other important accounts, and sign out of all active sessions wherever that option exists. Run a full malware scan. If that computer touches your bank, keep an eye on the account. And skip the shame spiral: this thing has caught IT professionals. Speed beats embarrassment.
Why this one's worth remembering
ClickFix spread because it neatly steps around ten years of security software — when you run the code yourself, there's no malicious download to intercept. It's now basic internet literacy, same shelf as "don't open strange attachments." The test on your screen is fake. Knowing that is the only verification that counts.
Image: Fernando Arcos, via Pexels





