Skip to content

Topic

ClickFix-Style Social Engineering

Social-engineering technique that uses fake CAPTCHA, error, or verification prompts to trick users into running attacker commands, often delivering malware.

Current stories

security4 publishers

Attackers move the ClickFix paste into Windows Terminal to land a multi-stage intrusion chain

Microsoft's TerminalFix writeup shows the same fake CAPTCHA lure now feeding multi-line PowerShell into Windows Terminal, where it sideloads a signed binary, pulls payloads out of PNG files and leaves a reverse tunnel behind.

Perspective Coverage

4 publishers
Builder
Builder 20%
Operator
Operator 75%
Investor
Investor 5%

Reality

Evidence65
Adoption
Insufficient
Hype gap+20
Incentives30
Confidence65

Earlier coverage

  1. ClickFix operators install the signed Deno runtime to run their remote JavaScript

    Security · August 14, 2026 · 1 publisher

  2. Bring Your Own Runtime: Sophos MDR maps a repeatable Deno-based intrusion chain

    Security · August 14, 2026 · 1 publisher