A new, sophisticated ClickFix combines the impersonation of trusted news sources (BBC News) with fake security verification alerts (Cloudflare Verification) to trick users into executing malicious commands on their systems.

How the Attack Works
The attack begins with a supposedly legitimate online advertisement or search results. After clicking, victims are redirected to a convincing copy of a BBC news website (with articles stolen from legitimate sources). However, the fake website acts as a distribution mechanism for malware.
See also: Misusing Microsoft Help Index Files to execute PipeMagic malware
After browsing the fabricated news site, users encounter what appears to be a typical security verification Cloudflare. These pages are exact replicas of the original Cloudflare Turnstile challenges, complete with authentic logos and Ray ID footers, adding a sense of legitimacy.
The fake verification page displays the familiar “Verify you are human” box that users are used to seeing online. However, when users attempt to complete verification, they are instructed to perform a series of seemingly routine actions:
1. Press Windows + R to open the Run dialog.
2. Press Ctrl + V to paste a verification command.
3. Press Enter to run the command.
Clicking the verify button loads a malicious PowerShell command into the system clipboard. The command that victims paste and execute is not a legitimate verification tool, but malicious code designed to download and install various types of malware.

The ClickFix technique has seen explosive growth during 2024 and 2025. According to 's Threat Report ESET, ClickFix attacks increased by over 517% in the first half of 2025.
See also: Phishing: Noodlophile malware distribution with new “bait”
This social engineering technique exploits users' natural tendency to quickly resolve technical issues, particularly when presented with genuine prompts from trusted services like Cloudflare. The effectiveness of the attack lies in its ability to bypass traditional security measures, convincing users to execute malicious code on their own systems voluntarily.
ClickFix attack: Different variations
Cybersecurity researchers have identified multiple variations of this attack, targeting different platforms and services. In addition to the fake BBC news sites, the attackers are impersonating other trusted entities, including Microsoft, Google Chrome, and transportation and logistics software.
Security companies report that ClickFix attacks lead to the development of info-stealer malware, ransomware, remote access, cryptominers , etc. Popular malware families that have been spread through these campaigns include Lumma Stealer, DarkGate, AsyncRAT, and NetSupport.
What makes these attacks particularly worrisome is their sophisticated evasion capabilities . Malicious PowerShell commands often retrieve Base64-encoded payloads from legitimate-looking services and include anti-parsing features that terminate execution (if they detect virtual machine environments). This allows them to evade traditional security scanning and achieve zero detection on many antivirus platforms.
See also: PyPI: Malicious packages exploit dependency for supply chain attacks
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Fake Cloudflare pages are professionally crafted to include authentic marketing text copied directly from the official Cloudflare website, making them extremely convincing.

Ways of protection
Organizations and individuals can take several measures to protect themselves from these attacks:
- Disabling the Windows Run dialog through Group Policy or registry modifications (to prevent malicious commands).
- Training users to recognize fake verification screens and suspicious command lines.
- Behavior monitoring application to detect unusual PowerShell or command line activity.
- Maintaining up-to-date security software with behavioral analysis capabilities.
Users should keep in mind that legitimate services, such as Cloudflare, never require users to interact directly with their operating system or execute terminal commands as part of their verification processes. Any website that requests such actions should be immediately considered suspicious.
Source: cybersecuritynews.com
