ClickFix
An attack where victims run the malicious code themselves, following instructions from a fake verification step or error fix.
Full definition
ClickFix is a social engineering technique where the victim runs the malicious code themselves. A fake page shows a supposed security verification or an error that is fixed by following a few steps: copy a command, open the system's run dialog and paste it. That command downloads the malware.
The technique bypasses much of the technical defense stack because there is no attachment or download for a filter to block: the action happens on the user's own machine, outside the reach of email security. Variants such as FileFix change the mechanism but keep the principle of turning the victim into the executor.
The response combines blocking command execution for users who do not need it with training one simple principle: no legitimate verification ever asks you to paste commands into your system.
Related terms
Social engineering
Psychological manipulation that leads a person to hand over information, access or money. It is the starting point of most successful cyberattacks.
Malware
Any software designed to damage, spy on or take control of a system without authorization. It almost always needs a person to let it in.
Infostealer
Malware that silently steals credentials, cookies and browser data, packaging them for sale on the dark web as stealer logs.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.