Security Alert

ClickFix Scams Use Fake CAPTCHAs to Distribute Malware

2 min read

On June 10, 2026, Google’s Security Blog warned of escalating “ClickFix” campaigns. These attacks guide users through highly realistic fake CAPTCHA prompts or fake browser update alerts to trick them into manually executing malicious code, effectively bypassing automated security scanners by relying on human error.

The Psychology of ClickFix

The ClickFix tactic is devastatingly clever because it exploits our conditioned internet behavior. We are used to solving CAPTCHAs to prove we are human, and we are used to clicking “update” when prompted by our software.

In a typical ClickFix attack, a user is redirected to a malicious page that throws up an error or a fake “Verify you are human” screen. Instead of asking you to click pictures of crosswalks, the fake CAPTCHA instructs you to press a specific combination of keyboard shortcuts—often opening the command line or run dialog—and then prompts you to paste in a string of text. Because the user manually executes the command, the operating system views it as an authorized action, allowing the malware to bypass traditional antivirus blocks entirely.

The Danger of Malicious Redirects

This attack thrives on the web’s clutter of pop-ups and redirects. Users often end up on ClickFix pages after clicking a deceptive download button, interacting with a shady advertisement, or being aggressively redirected from a low-quality streaming site. The fundamental issue is that the modern web allows too much unprompted behavior. When websites can spawn pop-unders or forcibly redirect your active tab, it creates the perfect environment for social engineering attacks to ambush unsuspecting users.

Stopping the Redirects with ProBlocker

Preventing a ClickFix attack is best achieved by never seeing the fake prompt in the first place. ProBlocker provides critical defense against this.

ProBlocker blocks ads, trackers, and, crucially, pop-ups and malicious redirects at the network level. By using filter lists like EasyList and uBlock Origin filters, ProBlocker stops the deceptive ads and forced redirects that funnel users toward ClickFix landing pages. It acts as a shield against the aggressive web mechanics that scammers rely upon. ProBlocker operates locally, collecting zero user data, and ensures you maintain control over where your browser goes.

Practical Takeaways

  • Block pop-ups and redirects: Use an ad blocker like ProBlocker to prevent malicious sites from ambushing you with fake prompts.
  • Never paste code: Never copy and paste text into your command prompt, PowerShell, or Run dialog simply because a website asked you to “verify” yourself.
  • Update carefully: Only update your browser or software through the application’s official settings menu, never from a random web pop-up.
ClickFix is a social engineering attack that uses fake prompts, like a CAPTCHA or browser update, to trick you into manually executing malware on your computer.