Guides & Reviews
Sep 18, 2026

What Is ClickFix? Why Fake CAPTCHAs Tell You to Run Commands

Learn why fake CAPTCHA and verification pages ask you to run PowerShell or Terminal commands, and what to do if you already followed the instructions.

AI-assisted, source-linked analysis. Product testing is only claimed when explicitly documented. .

If a website says you must open the Windows Run dialog, PowerShell, Windows Terminal, or macOS Terminal and paste a command to prove you are human, do not run it. That is not a normal step in ordinary web verification. It is a strong sign of a ClickFix-style social-engineering attack.

ClickFix is not one virus. It is a technique that persuades you to launch the attacker's command yourself. The command and its consequences vary by campaign: it may retrieve more code, run malware, steal information, or give an attacker remote access. Simply seeing the prompt is different from executing it.

What is ClickFix?

ClickFix is a social-engineering technique in which a page presents a problem and then offers a convincing-looking “fix.” The page might imitate a CAPTCHA, human-verification check, download page, software update, document error, or browser warning. Its instructions ultimately lead the visitor to copy, paste, and execute a command on the computer.

Microsoft's technique-level analysis describes campaigns using the Windows Run dialog, Windows Terminal, or PowerShell. Microsoft has also documented macOS campaigns that direct users to Terminal.

That makes ClickFix a delivery method rather than a single malware family. Different attackers can put different instructions behind the same kind of lure. Proofpoint has observed the technique used by multiple threat groups and leading to several different malware families. It would be misleading to say that ClickFix always installs one particular stealer or remote-access tool.

What does a fake ClickFix CAPTCHA look like?

The details change, but the important warning sign is the jump from a browser interaction to manual operating-system commands. A page may:

  • show a familiar-looking “Verify you are human” box;
  • claim that verification failed or an error must be fixed;
  • tell you to press Win+R, open PowerShell, or launch Windows Terminal;
  • tell a Mac user to open Terminal;
  • copy text to the clipboard, then instruct you to paste and press Enter;
  • claim the command is a verification, update, download, or repair step.

A familiar logo is not proof that the page is genuine. Microsoft's August 2026 TerminalFix research describes a fake Cloudflare-style CAPTCHA overlay; it does not report that Cloudflare itself was compromised. In separate macOS research, Microsoft found look-alike domains using spoofed branding and explicitly noted that the imitated service was not thereby compromised.

Not every fake CAPTCHA is ClickFix, and not every ClickFix lure uses a CAPTCHA. Focus on the requested action: an ordinary consumer-facing web verification should stay in the browser. It should not require you to paste an operating-system command.

Why does it ask you to run the command yourself?

The page is trying to turn a normal user action into the first execution step. You may be more willing to follow instructions that look like a routine check than to download an obviously suspicious program.

This also changes what the computer sees. Instead of double-clicking a conventional downloaded application, the user starts a trusted built-in tool and supplies the attacker's text. Microsoft's macOS research explains that a user-run Terminal command can avoid parts of the trust path normally applied to a downloaded app bundle. On Windows, Microsoft notes that ClickFix relies on human intervention and can get past some expectations and controls built around conventional files.

That does not make PowerShell, Terminal, or the Run dialog malicious. They are legitimate administrative and technical tools. The danger is an untrusted webpage directing an ordinary visitor to run text they have not independently verified.

ClickFix on Windows: Run, PowerShell, and TerminalFix

Traditional Windows ClickFix flows often tell the victim to open the Run dialog with Win+R, paste clipboard content, and execute it. Other versions tell the person to open PowerShell directly.

Microsoft uses TerminalFix for a variant that applies the same social-engineering idea but directs the victim to Windows Terminal or PowerShell instead of the Run dialog. In an August 28, 2026 campaign, compromised websites displayed a fake verification overlay and instructed users to execute a PowerShell command. That particular chain used multiple stages, persistence, reconnaissance, and a reverse-tunnel implant.

Those details belong to that campaign, not every TerminalFix incident. Another Microsoft investigation published in July 2026 found two ClickFix-led intrusion chains associated with ACR Stealer. The two chains began with the same broad social trick but diverged in how they delivered and ran later stages. This is why the safe conclusion is “the command may start an attack chain,” not “it always installs malware X.”

ClickFix on macOS

Mac users are also targeted. In the macOS campaign Microsoft described on August 5, 2026, look-alike download sites selectively showed a fake flow to visitors who appeared to be using a genuine macOS browser. The lure persuaded users to run a Terminal command that retrieved additional content. The documented chain ultimately delivered information stealers such as MacSync or Atomic Stealer.

Again, those payloads describe the observed campaign, not a universal ClickFix outcome. The durable warning is the same on both operating systems: a website should not need you to execute a shell command to complete an ordinary download, CAPTCHA, or human-verification step.

Does a real CAPTCHA ask you to open PowerShell or Terminal?

For ordinary consumer web use, no. A normal CAPTCHA might ask you to tick a box, solve an on-page challenge, or wait while the site evaluates browser signals. It does not need you to leave the browser, open an operating-system command tool, paste clipboard text, and execute it.

There are legitimate situations in which a developer, system administrator, or support professional uses a terminal. Those workflows should come from documentation or a trusted administrator whose identity and instructions you can verify independently. A surprise web page claiming that command execution is required to prove you are human is fundamentally different.

If a site blocks access unless you run a command, leave the page. Do not let urgency, a countdown, a copied command, or familiar branding override that rule.

What can happen if you run the command?

The result depends on the campaign and on the command that was delivered. A command can retrieve scripts or files, launch malware, create a way to run again later, steal browser credentials or session information, or establish remote access. It may also do something different that has not yet been identified.

Recent research illustrates that range:

  • Microsoft's August 2026 TerminalFix investigation documented a multistage Windows intrusion with persistence, network reconnaissance, and a reverse tunnel.
  • Microsoft's July 2026 ACR Stealer report described campaigns seeking browser credentials, authentication tokens, and sensitive documents.
  • Microsoft's August 2026 macOS report documented a chain delivering information stealers after the user ran a Terminal command.
  • Proofpoint's broader research has connected ClickFix delivery to multiple, unrelated payload families.

These examples establish plausible risks; they do not mean every command performs every action. You cannot safely judge a copied command from the reassuring explanation shown beside it, and this article deliberately does not reproduce commands or attacker URLs.

What should you do if you encountered a ClickFix prompt?

Your next step depends on how far the interaction went.

A. You saw the page but did not copy or run anything

Close the page and do not return through the same suspicious link, advertisement, or search result. Keep your browser, operating system, and security software current.

Merely seeing the lure is not the same as executing its command. The campaigns described here rely on the victim carrying out the instructions. That does not prove every suspicious page is harmless to view, but there is no reason to assume this ClickFix command ran when you did not execute it.

B. You copied the command but did not execute it

Do not paste or run it anywhere. Close the page. You can replace the clipboard contents by copying an ordinary piece of text, especially on a shared computer, and remain alert for follow-up prompts.

Copying text to the clipboard and executing it are different events. In the ClickFix chains discussed here, the user's paste-and-run action is the crucial execution step. Do not “test” the command, even in another command window.

C. You executed the command

Treat the device as potentially compromised, without assuming that every possible consequence occurred.

  1. If suspicious activity is continuing, disconnect the device from Wi-Fi or Ethernet to limit further communication. If it is a work-managed device, contact your IT or security team immediately and follow its incident process.
  2. From a trusted security interface—not a prompt supplied by the suspicious page—update your security tool's threat intelligence where it is safe to reconnect, then run a full scan. On Windows, Microsoft documents full and offline scan options.
  3. Review important account and session activity. Revoke sessions you do not recognize. If credential or session theft is plausible, change important passwords from a known-clean device and enable multifactor authentication or passkeys where available.
  4. Seek professional help if the scan reports a threat, the device behaves unexpectedly, sensitive accounts were exposed, or you cannot establish what the command did.

One clean antivirus scan does not prove with certainty that the machine is uncompromised. Different campaigns use different stages and persistence methods, and no scanner detects every threat at every moment. Preserve any incident details your organization or a security professional may need, but do not rerun the command to capture them.

How to recognize similar attacks

Pause when a page combines a routine task with unusual system-level instructions. Common warning signs include:

  • verification steps that leave the browser and open Run, PowerShell, Windows Terminal, or macOS Terminal;
  • a button that silently copies text, followed by instructions to paste it elsewhere;
  • an alleged browser, document, download, or update error fixed by running an unexplained command;
  • urgency or warnings that you will lose access unless you complete the command sequence;
  • a familiar brand displayed on a domain that does not belong to that service;
  • instructions from an advertisement, unsolicited message, redirect, or unexpected download page.

Compromised legitimate websites can be used in some campaigns, so a familiar domain is not always enough to make the instructions safe. Conversely, other campaigns use purpose-built look-alike domains. Evaluate the requested action as well as the address and branding.

Bottom line

ClickFix works by persuading you to execute the attacker's command. A fake CAPTCHA is one common disguise, but fake errors, downloads, and update prompts can use the same technique. TerminalFix and macOS variants show that the warning is not limited to the Windows Run dialog.

For an ordinary web verification, stop if the page asks you to open an operating-system command tool and paste text. If you did not run the command, close the page. If you did run it, treat the device as potentially compromised, use trusted security tools, protect important accounts from a clean device, and involve IT or a qualified professional when needed.