1 of 1
Story summary
- Security researcher Kevin Beaumont reports Reddit flooded with help requests for ClickFix attacks.
- ClickFix shows fake CAPTCHA pop-ups that tell users to copy, paste, and run code.
- Windows victims press Win+R, paste malicious text, and run PowerShell to download malware.
- TerminalFix bypasses Run-dialog blocks by sending users to the Win+X PowerShell menu.
- Russia’s state-sponsored actors and other APT groups use ClickFix, while Microsoft offers group-policy to disable the Start/Run prompt.
