{"id":1352,"date":"2026-08-20T13:01:43","date_gmt":"2026-08-20T11:01:43","guid":{"rendered":"https:\/\/www.cloudtango.net\/blog\/?p=1352"},"modified":"2026-08-20T13:01:43","modified_gmt":"2026-08-20T11:01:43","slug":"the-steep-rise-in-clickfix-style-phishing-attacks","status":"publish","type":"post","link":"https:\/\/www.cloudtango.net\/blog\/2026\/08\/20\/the-steep-rise-in-clickfix-style-phishing-attacks\/","title":{"rendered":"The steep rise in \u2018ClickFix\u2019 style phishing attacks"},"content":{"rendered":"<div class=\"wp-block-group blue\">\n<div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\">What is ClickFix?<\/h2>\n<p class=\"wp-block-paragraph\">ClickFix is a social engineering technique that the Security Operations team at CloudTech24 are seeing cybercriminals use to trick users into infecting their own devices.<\/p>\n<p class=\"wp-block-paragraph\">Typically, we find that a\u00a0<strong>user is redirected to a fake verification page that impersonates a trusted service such as Cloudflare, Google reCAPTCHA, or a website security check.<\/strong>\u00a0The page claims the user must complete a verification step before accessing the website.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Unlike traditional phishing attacks, the page does not ask for credentials.<\/strong>\u00a0Instead,\u00a0<strong>it instructs the user to copy and paste a command into the Run dialogue box (Windows) or Terminal (macOS) and execute it.\u00a0<\/strong>This command then downloads and runs malicious code directly on the user\u2019s device.<\/p>\n<p class=\"wp-block-paragraph\">These attacks are typically more successful due to these fake verification pages appearing on legitimate websites. The attackers will compromise a legitimate website that you may regularly use and then place the CAPTCHA\/Verification.<\/p>\n<\/div>\n<\/div>\n<h2 class=\"wp-block-heading\">The impact of an attack<\/h2>\n<p class=\"wp-block-paragraph\">A ClickFix campaign can result in:<br \/>\n&#8211; Malware installation<br \/>\n&#8211; Credential theft<br \/>\n&#8211; Command-and-control (C2) activity<br \/>\n&#8211; Unauthorised access to corporate systems<br \/>\n&#8211; Theft of sensitive data.<\/p>\n<p class=\"wp-block-paragraph\">In severe cases, it can provide attackers with persistent access to an environment and act as a precursor to ransomware or further compromise.<\/p>\n<div class=\"wp-block-group blue\">\n<div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\">Recommended response<\/h2>\n<p class=\"wp-block-paragraph\">If a user encounters a ClickFix style prompt, our cybersecurity specialists advise the following:<\/p>\n<ol class=\"wp-block-list\">\n<li>Do not copy or run any commands<\/li>\n<li>If you can, capture\/screenshot the URL, then close the browser tab immediately<\/li>\n<li>Report the incident to your IT\/Security team.<\/li>\n<\/ol>\n<p class=\"wp-block-paragraph\">If you have already run the command:<\/p>\n<ol class=\"wp-block-list\">\n<li>Disconnect the device from the\u00a0network<\/li>\n<li>Contact CloudTech24\u00a0immediately<\/li>\n<li>Do not attempt to clean the device yourself<\/li>\n<li>Assume any credentials used on that device are compromised and change them from a different device.<\/li>\n<\/ol>\n<\/div>\n<\/div>\n<div class=\"wp-block-group\">\n<div class=\"wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained\">\n<h2 class=\"wp-block-heading\">Concerned about phishing attacks?<\/h2>\n<p class=\"wp-block-paragraph\">CloudTech24 clients are welcome to schedule a call with their Customer Success Manager to discuss\u00a0phishing attacks. If you are interested in CloudTech24\u2019s\u00a0managed email security\u00a0and\/or\u00a0Managed Detection and Response (MDR) services,\u00a0<a href=\"https:\/\/cloudtech24.com\/contact\/\" data-type=\"page\" data-id=\"3940\">contact CloudTech24 today<\/a>. We can help you improve your cybersecurity and reduce risk.<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>What is ClickFix? ClickFix is a social engineering technique that the Security Operations team at CloudTech24 are seeing cybercriminals use to trick users into infecting their own devices. Typically, we find that a\u00a0user is redirected to a fake verification page that impersonates a trusted service such as Cloudflare, Google reCAPTCHA, or a website security check.\u00a0The[\u2026] <a class=\"read-more\" href=\"https:\/\/www.cloudtango.net\/blog\/2026\/08\/20\/the-steep-rise-in-clickfix-style-phishing-attacks\/\">Read<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" enable-background=\"new 0 0 24 24\" height=\"16px\" viewBox=\"0 0 24 24\" width=\"16px\" fill=\"#091926\"><rect fill=\"none\" height=\"16\" width=\"16\"\/><path d=\"M14.29,5.71L14.29,5.71c-0.39,0.39-0.39,1.02,0,1.41L18.17,11H3c-0.55,0-1,0.45-1,1v0c0,0.55,0.45,1,1,1h15.18l-3.88,3.88 c-0.39,0.39-0.39,1.02,0,1.41l0,0c0.39,0.39,1.02,0.39,1.41,0l5.59-5.59c0.39-0.39,0.39-1.02,0-1.41L15.7,5.71 C15.32,5.32,14.68,5.32,14.29,5.71z\"\/><\/svg><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-1352","post","type-post","status-publish","format-standard","hentry","category-cybersecurity"],"_links":{"self":[{"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/posts\/1352","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/comments?post=1352"}],"version-history":[{"count":2,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/posts\/1352\/revisions"}],"predecessor-version":[{"id":1361,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/posts\/1352\/revisions\/1361"}],"wp:attachment":[{"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/media?parent=1352"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/categories?post=1352"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/tags?post=1352"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}