Prove You're Human... Install This Malware - ClickFix
A familiar website check turns into a request to run a computer command. The trick depends on you treating a very different task like the same old interruption. You do not need to know code to know where to stop.
Incident overview
Netskope reported more than 5,400 compromised websites connected to an operation using fake verification prompts and other delivery methods. Some prompts asked visitors to run a command. The website total is not a count of infected visitors.
Why it works
A repeated interruption can receive less attention over time. Connor uses habituation to explain why a familiar-looking check may slip into the background, even when the action it asks for has changed. That is an interpretation, not a measured cause for this campaign.
Protective actions
- Never run a computer command to complete a CAPTCHA.
- Close a page that asks you to open PowerShell, Terminal, or another command tool to prove you are human.
- If you already ran the command, do not rely on closing the page. On a work device, contact IT or security promptly and explain what happened.
Video companion
Watch the breakdown
Wait. The task changed.
You wanted to visit a website. First, apparently, you need to find every motorcycle. Including that tiny corner of a tire, because now that is your job.
A CAPTCHA is a test intended to distinguish a person from an automated visitor. Most of us just want to finish it and get on with the page.
ClickFix takes advantage of that desire to get through a supposed problem. A fake check tells you to open a command tool and paste an instruction. Following it can download and run malware. What looks like one more verification step has turned into permission to run someone else's code.
Ordinary websites, unfamiliar instructions
Netskope's September 3 investigation found the operation across more than 5,400 compromised sites, including ordinary small-business websites and shops. Researchers did not establish how those sites were initially compromised or how many visitors ran the commands.
The report also describes a separate browser-based variant. Not every site or visitor necessarily encountered the same fake CAPTCHA. Nor does the website count tell us how many people were infected.
You do not need the full technical chain to use the lesson: a familiar setting does not make every new instruction part of a normal visit.
When the interruption becomes background noise
Habituation means our response to something gets weaker with repeated exposure. Think of a loud fan that bothers you when it starts, then gradually fades into the background.
An online interruption can become something to get past instead of something to reconsider. The danger is treating a changed request as the same old task. That does not make the person careless. It makes the change worth noticing.
Anderson and colleagues' 2015 study showed 25 participants repeated images of security warnings while measuring brain activity. Visual-processing responses declined with repetition, with a drop apparent by the second viewing. Warnings that changed appearance resisted that decline better.
This was not a study of fake CAPTCHAs or infection rates. It supports the habituation concept, not a claim that it caused every decision in this campaign. We also cannot estimate how many visitors complied from the website total.
One rule you can use without learning code
Never run a computer command to complete a CAPTCHA.
If a page asks you to open a system command tool to prove you are human, close it. You do not need to work out what the command does before declining it.
If you already ran it, closing the browser does not undo a program that started. For a work device, tell your IT or security team what happened. For a personal device, use your operating system's official security guidance or trusted technical help, not a support link supplied by the suspicious page.
You came to use the website. Running a stranger's code was not part of the deal.
Sources
- Malware on the Blockchain: An Ongoing Campaign's New WebRTC Twist (opens in a new tab)
Netskope · September 3, 2026
Supports: Observed website scale, fake verification mechanism, separate WebRTC variant, and unknown initial compromise method.
- Think before you Click(Fix): Analyzing the ClickFix social engineering technique (opens in a new tab)
Microsoft Threat Intelligence · August 21, 2025
Supports: Background on the broader technique and the danger of executing instructions disguised as a fix.
- How Polymorphic Warnings Reduce Habituation in the Brain: Insights from an fMRI Study (opens in a new tab)
ACM CHI 2015
Supports: Anderson and colleagues' warning-image research, not a test of CAPTCHA scams or malware infections.
- Prove You're Human... Install This Malware - ClickFix (opens in a new tab)
CyberPsych with Connor · September 8, 2026
Supports: Verified publication metadata and Connor's habituation framing. The article is a sourced adaptation, not a transcript.
Related cases
Video breakdownIt Blocked Ads... and Shared Your Account Access - Twitch
The Twitch extension really did make streams better. That did not answer a separate question: what was it doing with users' account access? A useful feature and a security problem can exist at the same time.
Video breakdownThe Internet Still Trusts Dead Websites - Sable Squirrel’s 10,000-Domain Network
Sable Squirrel controls more than 10,000 domains, many acquired after earlier owners let them expire. A familiar address can keep its reputation even when the person behind it has completely changed.
