ClickFix , the social engineering technique that tricks users into executing malicious code themselves, has evolved into a full-fledged API-driven malware delivery system . New research reveals that the malicious commands behind fake “ prove you’re human ” pages are now generated by backend servers that operate as an on-demand service, giving each visitor the same malware in a different packaging. The same research also uncovered a new delivery method designed to bypass Windows script scanning .
See also: ClickFix campaigns expand malware distribution with new loaders and fake updates

Security researcher Bert-Jan Pals analyzed several ClickFix and examined about 3,000 payloads from active campaigns. He presented his findings at OrangeCon in early June and published the details on June 30, 2026.The technique is simple in design: a decoy page displays a fake CAPTCHA or error message, hidden JavaScript places a command on the clipboard, and the page prompts the user to press a key combination, paste it, and press Enter — executing the malware.
The technique’s effectiveness is undeniable. ESET recorded a 517% from late 2024 to the first half of 2025, while the Microsoft 2025 Digital Defense Report ranks it in 47% of initial access cases detected by the Defender Experts. The technique now has its own MITRE ATT&CK as T1204.004, underscoring the severity of the threat.
ClickFix: How API-driven malware delivery works
The key finding of the research concerns how the payloads are generated . Pals found that ClickFix pages get their commands from backend servers that operate as an on-demand service: they accept requests, check an access token , log the caller, and return a fresh, randomized command each time. When he asked a server for 100 payloads , he received 100 different ones , wrapped in an alternating combination of Base64 , AES , TripleDES , Rijndael , and Deflate . Unpacking them, they all get unpacked into the same script, which runs in memory via a PowerShell runspace . The same platform serves bait in 25 languages and adapts the command to the visitor’s operating system, with versions for macOS running alongside those for Windows .
The commercialization of ClickFix doesn’t stop at the surface. ESET has identified criminals selling ready-made ClickFix builders to other attackers. Pals discovered a parallel commercialization one level deeper, in the way each payload is generated on demand. This Malware-as-a-Service (MaaS) model allows low-tech attackers to conduct sophisticated campaigns, dramatically increasing the number of potential victims.
See also: Mac: New ClickFix attack abuses Script Editor

ClickFix and AMSI Bypass: The New Method of Avoiding Detection
The second major finding concerns a new method that directly targets defense mechanisms. Instead of copying a malicious command to the clipboard, the newest ClickFix variant copies a seemingly innocent “ orchestration ” command. The page silently downloads a file to the Downloads folder , and the clipboard receives a short command that moves that file, unzips it, and executes the script inside it. Because the pasted line is only the orchestrator and not the payload itself , it is designed to bypass AMSI — the Windows feature that allows antivirus to scan scripts before they are executed. The malicious code is located in the downloaded file, outside the scope of the scan.
Execution has also shifted towards stealth. The original 2024 decoy directed users to press Windows+R and paste into the Run. A newer version, common in 2025 and into 2026, directed them to Windows+X and the Windows Terminal. The Terminal seems more common, and unlike the Run, it leaves no trace in the RunMRU that incident investigators typically look for.
ClickFix has now been adopted by state actors. Proofpoint has linked Russian , Iranian , and North Korean state-backed groups — including APT28 , MuddyWater , and Kimsuky — to campaigns that incorporated ClickFix into their existing infection chains. In addition, over 700 websites Ghost CMS have been compromised via the CVE-2026-26980 (SQL injection) vulnerability, delivering ClickFix payloads to visitors from institutions such as Oxford and Harvard .
See also: Microsoft: New ClickFix campaign distributes Lumma Stealer

To protect against ClickFix, organizations should train users to recognize decoys, deploy EDR to detect unexpected PowerShell after web browsing, and use only official package managers (pip, npm, brew) to install tools. End users should never copy and paste PowerShell from fake error screens or CAPTCHAs. The evolution of ClickFix into a full MaaS framework highlights the need for proactive defense that combines user education, behavioral monitoring, and strict software installation policies.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
