ClickFixFileFixsocial engineering

    July 27, 2026 · 7 min read · By Fensivo Team

    What ClickFix and FileFix are: the victim runs the attack

    Leer en español

    The bottom line: ClickFix does not exploit a system flaw, it exploits a person's willingness to follow an instruction

    ClickFix is a social engineering technique that convinces a person to copy a command and paste it into their own computer to, supposedly, fix a problem: a document that will not open, a video that will not load, a "verify you are not a robot" box that never clears. The command fixes nothing. It installs the attacker's software and the victim runs it themselves, without any malicious file ever having to slip past a filter. FileFix is the most recent variant of the same idea, leaning on the file explorer's address bar instead of the command window.

    What makes this family of attacks dangerous is not a technical flaw, it is a role reversal: the machine was not breached, the person was persuaded to breach it on the attacker's behalf. That is why the defense does not live in the security console, it lives in the behavior of whoever receives the instruction and decides to follow it. Understanding the mechanism matters, but preparing for it is something else, and that is where we want to dwell.

    What ClickFix is and how it arrives

    ClickFix almost always starts where most attacks start: in the inbox, or on a lure page that an email points to. CISA estimates that more than 90 percent of successful cyberattacks begin with a phishing email, and ClickFix is no exception, it only changes what the email asks for. Instead of an attachment to open or a link where you hand over your password, the message leads to a page that fakes an error and offers a "fix" in three steps.

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment

    The script is recognizable once you have seen it: the page shows an official-looking notice (a pending update, a CAPTCHA that will not pass, a shared document that "needs a quick adjustment"), followed by a friendly, detailed instruction. Copy this text. Open this window. Paste it. Press Enter. Each step, on its own, looks harmless. The damage is in the sum, and the person completes the sum.

    The twist: the person pastes and runs the attacker's command

    The point that sets ClickFix apart from classic phishing is who pulls the trigger. In traditional phishing, the person hands something over (a credential, a click on a link) and the attack continues on the other side. In ClickFix, the person runs the attack on their own machine. The command they copied, almost always obfuscated so it means nothing at a glance, downloads and runs the attacker's program with the permissions of the user who pasted it.

    It works for a very human reason: the person believes they are fixing something, not that they are being attacked. Whoever follows the steps does not feel they are lowering their guard, they feel they are clearing an annoyance. Cisco's 90-5-5 framework, which estimates that roughly 90 percent of breaches involve a human factor, describes exactly this terrain: not clumsiness, but a risk surface that activates when someone, in good faith, does what they are asked under a believable pretext. ClickFix is designed to land inside that 90 percent.

    What FileFix is, the variant that abuses the file explorer

    FileFix was born in response to many companies starting to watch or block the command window. If the terminal raises suspicion, the attacker looks for another familiar surface, and found one in the file explorer. The lure page asks for something seemingly routine: "to view the document, copy this path and paste it into your folder's address bar". That bar, which most people use only to move between folders, can also run instructions, and the pasted text hides the same old command disguised as a path.

    The lesson of FileFix is not to memorize exactly where the command gets pasted, because tomorrow it will be somewhere else. The lesson is that the technique changes surface with ease: today the terminal, yesterday the Run window, now the explorer. The only stable part, the one thing that does not change between variants, is the step where a person copies something they do not understand and runs it because a screen asked them to, confidently.

    Why no filter stops what the person runs themselves

    Email and network controls are built to intercept a malicious object: an attachment with a known pattern, a link on a blocklist, a file that misbehaves when opened. ClickFix and FileFix avoid almost all of that because they do not send the object. They send text. An instruction sheet and a command on the screen do not trip the same alarms as an attached executable, and when the command finally runs, it does so from a legitimate user action, in their session, with their permissions. To many defenses, that looks like normal activity.

    It is the same pattern we have seen in other vectors that surround traditional email without replacing it. The malicious QR code pulls the link out of the message body and puts it in an image the filter cannot read, as we explain in our article on quishing. Generative deception makes the pretext more convincing, a topic we cover when discussing AI phishing and deepfakes. ClickFix adds a twist of its own: it does not ask the technology to fail, it asks the person to act. And against a voluntary user action, the filter arrives late by design.

    How to prepare and validate behavior against this pretext

    If the attack completes in a human decision, preparation has to happen in the same place: before the decision, not after the incident. Teaching once a year that "you should not paste strange commands" does not change behavior in the moment an urgent, believable, well-written screen asks for exactly that. What changes behavior is having lived through the pretext in a safe setting, having felt the pull to fix things fast, and having learned to stop at the precise step where the attack needs the person's cooperation.

    And preparing is not enough if it is not checked. Human Risk Management (HRM), the category that groups this approach, starts from an uncomfortable idea: having taken a training course does not prove that behavior changed. What proves it is putting the person back in front of a pretext from the same family weeks later, in a different disguise, and seeing whether this time they stop. That later validation, the retest, separates those who understood the mechanism from those who merely remembered one email. With a technique that shifts surface as fast as ClickFix and FileFix, validating that the person learned the pattern, and not a single case, is what holds the defense together over time.

    At Fensivo we work that terrain: we prepare people's behavior against realistic email-borne pretexts, deliver specific training the moment someone falls, and validate with retest that the lesson holds rather than that it was memorized. It is the approach we apply to the social engineering defense use case, where the goal is not to add courses but to confirm that behavior holds up the next time.

    If tomorrow a convincing screen asked someone on your team to copy a command and paste it "to fix" a document, do you know how many would stop at the right step, and how you would check?

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment