ClickFix Attack Analysis: Why ClickFix Accounts for 47% of Initial Access
ClickFix doesn't rely on software vulnerabilities. It exploits human trust. By disguising malicious instructions as error fixes, CAPTCHA checks, or installation guides, it convinces users to copy, paste, and execute malicious commands themselves.
This approach has helped ClickFix spread rapidly. According to Microsoft, it was the most common initial access method observed, accounting for 47% of attacks. Because the user is the one running the command, the activity looks legitimate, making it difficult for security solutions to detect in advance.
AhnLab SEcurity intelligence Center (ASEC)'s latest report analyzes how ClickFix works, the disguises attackers use, how it has evolved, and how organizations can respond.

What Is ClickFix?
After Microsoft began blocking macros in files downloaded from the internet by default in 2022, threat actors shifted to alternative distribution methods. First observed in March 2024, ClickFix takes a different approach by targeting human psychology instead of technical flaws. Rather than performing malicious actions directly, the threat actor turns the user's own troubleshooting behavior into the starting point of the attack.
How a ClickFix Attack Unfolds
The attack follows a simple sequence: a fake error or warning screen appears, instructions explain how to "fix" it, JavaScript silently copies a malicious command to the clipboard, and the user pastes and runs it in the Run dialog or Terminal. Legitimate system tools such as PowerShell, mshta, and curl then download or execute additional payloads, sometimes directly in memory.
Disguises Built on Everyday Problems
ClickFix can imitate almost any message users encounter in daily life. The report examines nine lure types, including fake CAPTCHAs, corrupted documents, video conferencing errors, fake Blue Screens of Death, failed updates, account authentication errors, development build errors, job interviews, and even responses from AI tools. Cloned installation pages for popular AI development tools have also been used to distribute infostealers to both Windows and macOS users.
From Cybercrime to State-Sponsored Campaigns
What began as a cybercrime technique has been adopted by state-sponsored groups such as APT28, Lazarus, and Transparent Tribe, as well as major ransomware groups. Notably, many of these groups did not build new campaigns around ClickFix. They simply replaced their initial execution phase with it, showing how low the barrier to adoption is.
Expanding Beyond Windows
ClickFix now targets macOS and Linux environments, developers, and AI agent users. Derivative techniques such as FileFix, CrashFix, InstallFix, ConsentFix, and PromptFix have modified how execution is triggered, from File Explorer address bars and real browser crashes to OAuth authorization codes and AI agents. Even Apple's new macOS Terminal paste warning was bypassed within two weeks of its introduction.
Why Traditional Defenses Struggle
ClickFix often involves no email attachment or malicious link, leaving email and network security with little to block. Since malicious behavior begins only after the user executes the command, sandboxes find it hard to detect in advance, and on the endpoint, the activity appears to come from legitimate system processes.
How to Respond
The report outlines a multi-layered defense built on three pillars: behavior-based detection of clipboard-based command execution and abnormal process chains, endpoint policies based on least privilege to restrict the misuse of legitimate tools, and user awareness training that shifts from "don't click" to "don't paste." It also includes detailed detection points, recommended security controls, and MITRE ATT&CK mapping.
- AhnLab