CyberPlay

ClickFix: “Prove you’re human”

Fake CAPTCHAs and “repair steps” that make you install the malware yourself

“ClickFix: “Prove you’re human”” is a free CyberPlay video course of about 7 minutes. A guide explains the topic and the video stops for five questions.

Learn to spot fake “verify you are human” pages and fake error screens that tell you to press Win + R and paste a command. You will know why a real check never leaves the browser and what to do if you already ran one.

Start the course

ClickFix: “Prove you’re human”

Key facts

  • Five checkpoint questions inside the video
  • About 7 minutes
  • Guides to choose from: 7
  • Narrated in English and Romanian
  • Free with a CyberPlay account
  • Certificate of completion with Individual Plus or an organisation plan that includes certificates
  • Up to 160 XP the first time you finish

What you will be able to do

  • A real check stays inside the browser.
  • Win + R, Terminal or “paste this” from a website = malware. Close the tab.
  • If it happened: disconnect, tell someone, change passwords from another device.

A web page tells you to “verify you are human” or “fix this error”, then asks you to press a few keys. It looks harmless, but those keys run a hidden command that installs malware on your own device. This page explains how the trick works and the one rule that stops it.

What it is

ClickFix is a social engineering trick. In a post dated 13 March 2025, Microsoft described it as fake error messages or prompts that tell you to fix a problem by copying, pasting and launching a command, which ends with malware being downloaded. You do the last step.

It is common. In its Digital Defense Report 2025 (October 2025), Microsoft said ClickFix was the most common first step in the attacks its Defender Experts handled between July 2024 and June 2025: 47% of cases. That is Microsoft's own incident data, not all attacks. In its 2026 Global Threat Report (24 February 2026), CrowdStrike counted 563% more incidents using fake CAPTCHA lures in 2025 than in 2024.

How it works

  1. You land on a trap page. It can arrive through a phishing email, a malicious ad, or a real website that criminals have hacked.
  2. A fake check or error appears. It may copy the Cloudflare or Google “I’m not a robot” box, show a browser error with a “copy fix” button, or fake a Windows Update.
  3. Your click copies a command. The page quietly puts a command on your clipboard. You never see it.
  4. The page gives you “steps”. Press Windows + R (opens the Run box, which starts programs), then Ctrl + V (pastes the hidden command), then Enter (runs it). Variants send you to Terminal or PowerShell, or ask you to paste a “file path” into File Explorer (named FileFix by the researcher mr.d0x, 23 June 2025). On a Mac, the page sends you to Terminal and then asks for your password (CloudSEK, 4 June 2025).
  5. Windows runs it for the attacker. Usually PowerShell, which pulls the malware straight into memory. Microsoft calls this a fileless process, often invisible to traditional security tools.
  6. The malware steals. Infostealers take saved passwords, cookies, cards and crypto wallets. CISA, the FBI and partners (22 July 2025) warned that the Interlock ransomware gang used a fake CAPTCHA that tells people to open the Run window.

CrashFix is nastier. In a report dated 16 January 2026, Huntress described a malicious extension that crashes Chrome on purpose. When it restarts, a page claims “security issues detected” and asks for the same three keys.

Why does it work? Fixing things yourself feels smart, and after hundreds of checks one odd step stops feeling odd. Antivirus often misses it: no file is downloaded, and Windows' own tools run the command because you told them to.

Real cases

  • Lumma Stealer. On 21 May 2025, Microsoft said it had found more than 394,000 Windows computers infected with Lumma between 16 March and 16 May 2025.
  • Hotels. In a post dated 13 March 2025, Microsoft Security described a campaign that began in December 2024. Hotel staff got emails that looked like Booking.com, about a negative guest review. The link opened a fake CAPTCHA, and the three keys downloaded credential-stealing malware.
  • Romania and Berlin. On 14 August 2026, DCNews reported that rowater.ro, the website of Apele Române, showed a pop-up copied from Cloudflare's check: open Run, paste, press Enter. DNSC took it offline the same evening. On 7 September 2026, heise reported that Germany's BSI traced a breach of Berlin government departments to an employee who pasted such a command.

How to spot it

  • A “check” or “error” page tells you to press Windows + R, open Terminal or PowerShell, or paste into File Explorer.
  • It asks you to paste something you never typed and could not see.
  • It makes you leave the browser. Cloudflare's documentation says a real visitor is at most asked to check a box or select a button.
  • It rushes you with a countdown such as “verify within 60 seconds”.
  • It offers a “copy fix” button, or “repair steps” after your browser crashed.
  • On a Mac, it sends you to Terminal and then asks for your password.

What to do

  1. Stop. Do not press the keys. If the Run box is already open, close it. Do not paste.
  2. Close the tab. No real website needs you to run anything on your computer.
  3. Fix browser problems in the browser. Restart it and look in its settings. If it keeps crashing, remove extensions you do not recognise.
  4. Tell someone. At work or school, tell IT. At home, tell an adult.

If it already happened

  1. Disconnect from the internet and tell someone: IT at work or school, an adult at home. CISA's guidance for infected computers says the same. Say what you pasted and roughly when.
  2. Run a full scan with updated antivirus. IT may decide to reinstall the system.
  3. Assume your passwords and sessions are stolen. From another device, change important passwords (email first), sign out everywhere and turn on 2-step verification.
  4. Money or cards involved? Call your bank on the number printed on the card. Check crypto wallets too.
  5. Report it. In Romania, call 1911 (24/7) or use the DNSC site pnrisc.dnsc.ro. Fast reports protect other people, and there is nothing to be ashamed of.

Sources

  1. Microsoft Digital Defense Report 2025 — ClickFix 47% of initial access (Defender Experts) — Microsoft, Oct 2025
  2. Think before you Click(Fix): Analyzing the ClickFix social engineering technique — Microsoft Security, 21 Aug 2025
  3. Microsoft leads global action against favored cybercrime tool (Lumma Stealer, 394,000 PCs) — Microsoft, 21 May 2025
  4. Phishing campaign impersonates Booking.com, delivers credential-stealing malware (Storm-1865) — Microsoft Security, 13 Mar 2025
  5. ESET Threat Report H1 2025 — ClickFix detections +517% — ESET, 26 Jun 2025
  6. CrowdStrike 2026 Global Threat Report — fake CAPTCHA incidents +563% — CrowdStrike, 24 Feb 2026
  7. Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape — Proofpoint, 18 Nov 2024
  8. Around the World in 90 Days: State-Sponsored Actors Try ClickFix — Proofpoint, 17 Apr 2025
  9. CrashFix: malicious browser extension leads to fake crash repair page (KongTuke) — Huntress, 16 Jan 2026
  10. ClickFix malware buried in images (fake Windows Update lure) — Huntress, 24 Nov 2025
  11. FileFix — a ClickFix alternative — mr.d0x, 23 Jun 2025
  12. AMOS variant distributed via ClickFix in Spectrum-themed campaign (macOS) — CloudSEK, 4 Jun 2025
  13. Interlock ransomware joint advisory AA25-203A (ClickFix initial access) — CISA / FBI / HHS, 22 Jul 2025
  14. DNSC avertizează asupra ClickFix (tehnica prin care utilizatorii rulează singuri comenzi malițioase) — DNSC via Agerpres, 31 Jul 2026
  15. Site-ul Apele Române folosit pentru un posibil atac ClickFix; DNSC a închis rowater.ro — DCNews, 14 Aug 2026
  16. BSI explains first attack vector on Berlin authorities (TerminalFix) — heise, 7 Sep 2026
  17. Cloudflare Challenges — what a legitimate check does — Cloudflare Docs, 2026
  18. Recovering from Viruses, Worms, and Trojan Horses — CISA, 2019

Frequently asked questions

Is “ClickFix: “Prove you’re human”” free?

Yes. “ClickFix: “Prove you’re human”” is free with a CyberPlay account. Create an account to watch it, answer the five questions and keep your progress and XP.

How long does “ClickFix: “Prove you’re human”” take?

About 7 minutes, including the five questions. The exact length depends on the guide and the language you choose.

Do I get a certificate for “ClickFix: “Prove you’re human””?

Yes, with Individual Plus or an organisation plan that includes certificates. Finish the course and answer all five questions, then claim a certificate of completion that shows your first-attempt score.

Which languages is “ClickFix: “Prove you’re human”” available in?

The video is narrated in English and Romanian by a guide you choose (available: 7). The buttons and menus around it are available in nine languages.

All video courses

Contact · About