{
  "id": 7367086,
  "title": "ClickFix-based attacks are becoming widespread on both PC and Mac",
  "url": "https://urgent.news/2026/09/14/clickfix-based-attacks-are-becoming-widespread-on-both-pc-and-mac",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-14T17:50:00.000Z",
  "source": {
    "name": "TechSpot",
    "slug": "techspot",
    "url": "https://www.techspot.com/news/113840-clickfix-based-attacks-becoming-widespread-both-pc-mac.html"
  },
  "original_language": "en",
  "account": "Security researchers are sounding the alarm over the growing number of ClickFix-based attacks targeting both PCs and Macs. This social engineering technique is being employed in both simple and complex malicious campaigns, with users not paying enough attention to the requests made by strangers online. The attacks typically start with a pop-up displayed over a trusted website, prompting users to copy, paste and execute commands from the Windows or Mac command line. Cybercriminals are weaponizing CAPTCHA overlay windows to make these attacks more convincing.\n\nAccording to security researcher Kevin Beaumont, victims of ClickFix attacks are turning to Reddit for help. Cybercriminals are now compromising legitimate websites to launch new ClickFix-based attacks, making it easier to trick users into executing malicious commands from websites they frequently visit. Beaumont suggests that businesses in the Windows ecosystem could neutralize ClickFix and other prompt-based threats by disabling the Start/Run prompt functionality entirely. Microsoft offers specific group policies to limit access to this feature, although many companies may not deem it necessary.\n\nClickFix threats are particularly effective for spreading malware, as they do not require the establishment of a network infrastructure or the use of Microsoft-trusted certificates. With this technique, attackers can avoid rotating malicious domains and delivering malware packages. Russia's state-sponsored actors and other APT groups have already integrated ClickFix into their sophisticated attack methods. Even seemingly innocent elements, such as CAPTCHA windows in Google Sheets documents or blockchain-based smart contracts, can be compromised.\n\nSoftware vendors are attempting to combat the ClickFix security epidemic by developing new countermeasures for both Windows and Mac systems. However, malware developers are racing to create new attack methods that remain effective. The researchers warn that this security issue is far from being resolved and that the increasing number of users seeking simpler computing approaches is making it easier for cybercriminals.",
  "summary": "Typical ClickFix social engineering attacks begin with a pop-up displayed over a trusted web page that provides some pressing instructions. Cybercriminals have weaponized CAPTCHA overlay windows to make the social engineering attempt more effective, asking users to copy, paste and execute a covert command from the Windows or Mac command... Read Entire Article",
  "key_points": [
    "ClickFix attacks spreading to PCs and Macs, targeting users' attention to online requests",
    "Cybercriminals weaponize CAPTCHA overlay windows to make attacks more convincing"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}