Drooid Logo
Back to today’s briefing

Story perspectives

Reddit Flooded With ClickFix Phishing Code Attacks

By Drooid · · How we work

15 3 Full Breakdown

1 of 1

Story summary
  • Security researcher Kevin Beaumont reports Reddit flooded with help requests for ClickFix attacks.
  • ClickFix shows fake CAPTCHA pop-ups that tell users to copy, paste, and run code.
  • Windows victims press Win+R, paste malicious text, and run PowerShell to download malware.
  • TerminalFix bypasses Run-dialog blocks by sending users to the Win+X PowerShell menu.
  • Russia’s state-sponsored actors and other APT groups use ClickFix, while Microsoft offers group-policy to disable the Start/Run prompt.