Cybersecurity researchers have highlighted a dangerous cyber attack known as ClickFix, which is currently targetting users across Windows, Mac, and mobile devices.
Unlike traditional viruses that rely on hidden downloads, this scam relies on tricking you into manually installing the malware yourself under the guise of solving a routine web check.
How the Scam Works
You visit a website (often a compromised legitimate site, expired domain, or fake link) and a pop-up appears stating "Verify you are human", "Fix audio driver", or "Sign-in failed".
The page instructs you to follow quick verification steps—typically prompting you to open your system command line (PowerShell on Windows or Terminal on Mac) or press
Win + Rand paste a provided line of text.The moment you paste and press Enter, a hidden background script executes. This secretly installs info-stealing malware designed to hijack saved passwords, online banking credentials, and personal files.
How to Prevent This from Happening
Golden Rule: No legitimate company—whether Google, Microsoft, Cloudflare, or Meta—will ever ask you to open PowerShell, Command Prompt, or Terminal to prove you are a human or fix a browser issue.
Never Paste Unfamiliar Commands: If a website instructs you to press
Win + R, paste text into a command terminal, or download an unverified app to view a page, close the browser tab immediately.Beware of Artificial Urgency: Scammers rely on countdown timers and warning messages to trigger panic. Take a moment to think before following unusual instructions.
Keep Devices Updated: Ensure your operating system, web browsers, and anti-virus software are fully up to date with real-time web protection enabled.
What to do if you have already fallen for this: Immediately disconnect your device from Wi-Fi/Ethernet, change your key account passwords (email, online banking, social media) from a secondary secure device, and run a full system anti-virus scan or consult an IT professional.
Source: The Phone Guardian