Home · Technology · Sep 14 archive
ClickFix Attacks Spreading Rapidly Among PCs and Macs
Confirmed
In Short: ClickFix attacks, previously exotic, are now mainstream, exploiting user interaction to evade security tools.
Prior to ClickFix, attackers needed resource-intensive infrastructure to install malware, including SEO-manipulated download portals and Microsoft-trusted signing certificates. Now, the technique has become simpler and more effective, according to BlueVoyant.
These so-called “ClickFix” attacks have quickly become one of the rising cybersecurity threats of 2026, and they’re getting both sneakier and compromising people’s devices with greater frequency, according to TechCrunch.
As noted by Ars Technica, a tool for Mac users called BlockBlock can also defend against attacks that try to trick Apple users into hacking themselves. Security researchers now say that the latest ClickFix campaign they’ve seen involved hackers posting fake ads on Reddit, linking to a page that looks like HBO Max but contains a ClickFix lure that tricks people into hacking themselves.
What's confirmed
- Prior to ClickFix, attackers needed resource-intensive infrastructure to install malware, including SEO-manipulated download portals and Microsoft-trusted signing certificates. Now, the technique has become simpler and more effective, according to BlueVoyant.
- These so-called “ClickFix” attacks have quickly become one of the rising cybersecurity threats of 2026, and they’re getting both sneakier and compromising people’s devices with greater frequency, according to TechCrunch.
- As noted by Ars Technica, a tool for Mac users called BlockBlock can also defend against attacks that try to trick Apple users into hacking themselves. Security researchers now say that the latest ClickFix campaign they’ve seen involved hackers posting fake ads on Reddit, linking to a page that looks like HBO Max but contains a ClickFix lure that tricks people into hacking themselves.
What's still developing
- “Reddit is becoming post after post after post of people getting their computer infected via ClickFix,” independent researcher Kevin Beaumont observed Thursday.
- Typically, attacks begin with a simple CAPTCHA image, often masquerading as one from Cloudflare.
- “The pivot to ClickFix in late May 2026 eliminates the code-signing requirement entirely, substituting the legitimacy of a validly signed installer with a different form of legitimacy: a user voluntarily executing the malicious command in their own terminal,” BlueVoyant said.
- ClickFix attackers keep finding new ways to use public services—including publicly published Google Sheets documents, according to Cisco Talos.
- Simplicity—combined with the difficulty of getting stuff done—makes ClickFix ideal.
- It wasn’t that long ago that ClickFix attacks were exotic.
- Now the technique has become mainstream as attackers reap its simplicity and effectiveness in infecting users of PCs and Macs alike.
- Since the user is working in the computer’s terminal, which lets them interact directly with the operating system using text-based commands, many of these attacks evade antivirus and security defense tools.
