Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a3fec1ed5a9919ef

Jump to content

// Workers AI · dad joke modeWhat did ClickFix say to the mouse? You click with me.

From Wikipedia, the free encyclopedia
Example of a ClickFix style page.

ClickFix is a social engineering technique. It typically shows a popup over a webpage instructing the viewer to run a system command that will install malware.[1][2] It often contains an instruction to open the Run dialog on Microsoft Windows using the ⊞ Win+R shortcut.

History

[edit]

The first ClickFix version was discovered in October 2023.[3]

In March 2026, Apple added a mitigation to macOS to prevent ClickFix style attacks.[4][5] In April, a modified variant using the applescript:// URI scheme to bypass the use of the Terminal application was found.[6]

According to Hudson Rock, ClickFix often forms a feedback loop, using credentials stolen by infostealers to compromise administrative accounts on legitimate websites and host new ClickFix lures.[7] In July 2026, researchers detailed an incident where stolen WordPress credentials led to a ClickFix campaign on an Artlist subdomain using Polygon smart contracts (EtherHiding) for dynamic payload routing.[8]

Usage

[edit]

ClickFix was used in the 2026 ransomware attack on Berlin.

See also

[edit]

References

[edit]
  1. Fadilpašić, Sead (2025-11-07). "Experts warn ClickFix malware attacks are back, and more dangerous than ever before - here's how to stay safe". TechRadar. Retrieved 2026-04-09.
  2. Goodin, Dan (2025-11-11). "ClickFix may be the biggest security threat your family has never heard of". Ars Technica. Retrieved 2026-04-09.
  3. Fermo, Vincent; Gsas '26 (2025-10-15). "ClickFix: How Hackers Use 'Verification' to Steal Your Information". Fordham University Information Security and Assurance. Retrieved 2026-04-10.{{cite web}}: CS1 maint: numeric names: authors list (link)
  4. Toulas, Bill. "Apple adds macOS Terminal warning to block ClickFix attacks". BleepingComputer. Retrieved 2026-04-09.
  5. "I put Apple's new macOS ClickFix warnings to the test and they actually worked — now I want them on Windows too". Tom's Guide. 2026-03-31. Retrieved 2026-04-09.
  6. "New ClickFix variant bypasses Apple safeguards with one‑click script execution". CSO Online. Retrieved 2026-04-09.
  7. "From Victim to Vector: How Infostealers Turn Legitimate Businesses into Malware Hosts". Hudson Rock. 2025-12-30. Retrieved 2026-07-31.
  8. "How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist". InfoStealers. 2026-07-14. Retrieved 2026-07-31.

Further reading

[edit]
[edit]