Copy, Paste, Compromised: How ClickFix Attacks Work and How CrowdStrike Stops Them

September 29, 2026

• • Threat Hunting & Intel

Consider this hypothetical scenario: An employee tries to join what looks like a routine video meeting. The page loads, but instead of the meeting, they see an error message along with a helpful fix: Copy the provided command, open the Windows Run dialog, paste it, and press Enter. 

The meeting never starts. The command does something else entirely.

This is ClickFix, a social engineering technique that turns the victim into the mechanism for executing an attack. CrowdStrike Intelligence has observed adversaries including STARDUST CHOLLIMA and VOODOO BEAR using ClickFix in real-world operations. Further, the CrowdStrike 2026 Global Threat Report documented a 563% increase in incidents involving fake CAPTCHA lures in 2025. 

ClickFix is effective because it exploits something security teams cannot simply patch: a user's instinct to solve a problem. In this blog post, we explain what ClickFix is, how it works, and how CrowdStrike stops these attacks.

What Is ClickFix?

Instead of convincing someone to open a suspicious attachment, ClickFix gives them a seemingly legitimate reason to execute a command themselves. The “error” it presents might claim a meeting application needs to be repaired, a browser needs to be verified, or a CAPTCHA needs to be completed. 

Whatever the pretext, the objective is the same: Move malicious instructions from an adversary-controlled webpage into a trusted operating system tool. 

A typical ClickFix chain looks like this:

  1. The adversary creates the problem: The victim lands on a compromised site displaying a fake error, CAPTCHA, or system message. Depending on the sophistication of the attack, the adversary may use a phishing email or more targeted techniques to get them there.

  2. The website provides the "solution": The page instructs the user to copy a command. In some variants, malicious JavaScript may place the command directly onto the clipboard.

  3. The user crosses the security boundary: The victim is instructed to copy a command and paste it into the Windows Run dialog, PowerShell, Terminal, or another trusted system utility.

  4. The operating system executes the attacker's instructions: The command may launch PowerShell, VBScript, or another legitimate interpreter to retrieve or execute additional payloads.

  5. The initial command becomes an intrusion. Follow-on activity can include malware deployment, credential theft, persistence, command and control, data theft, or additional access into the environment, CrowdStrike observations show.

Why ClickFix Works

ClickFix takes advantage of common everyday enterprise behaviors. Employees regularly deal with broken meetings, authentication challenges, CAPTCHA prompts, browser errors, and application issues. A prompt telling someone to perform a quick troubleshooting step can feel far less suspicious than an unexpected executable or email attachment. 

The technique also relies on tools users recognize and trust. PowerShell, Windows Run, command shells, and scripting engines are legitimate parts of the operating system, and ClickFix takes advantage of them rather than asking the user to launch an unfamiliar program. 

Another defining characteristic is how the victim performs the critical action. Traditional phishing often depends on getting someone to download or open something malicious. ClickFix asks the victim to transfer the attack from the webpage into the operating system and initiate execution. By prompting the victim to run the command, the adversary evades security tools solely built to stop malicious files. 

The lure itself can also change quickly. A campaign does not need to depend on one long-lived phishing domain or one recognizable template. Adversaries can rotate domains, compromise legitimate websites, change the brands they impersonate, or swap a fake meeting error for a fake CAPTCHA while keeping the underlying technique the same.

CrowdStrike Intelligence observed this kind of infrastructure diversity in VOODOO BEAR activity, including websites of diverse Ukrainian entities (such as local government, energy, agriculture, and logistics entities) likely compromised to serve fake CAPTCHAs. The appearance of the attack may change, but the core behavior remains consistent: Convince the user to copy, paste, and execute.

STARDUST CHOLLIMA: From Fake Meeting to Malware

CrowdStrike Intelligence observed a ClickFix scenario likely involving STARDUST CHOLLIMA that demonstrates how quickly a routine browser interaction can lead to endpoint compromise. In July 2026, STARDUST CHOLLIMA very likely targeted an employee at a financial services entity using infrastructure masquerading as a video conferencing site.

When the employee attempted to join the meeting, they almost certainly encountered a fake technical issue accompanied by a command presented as the fix. Running that command triggered a PowerShell- and VBScript-based infection chain that deployed two previously unknown malware families: GeniexLoader and GeniexRAT. The lure worked by making a malicious command look like a reasonable fix for an ordinary meeting problem.

VOODOO BEAR: A Different Approach with Fake CAPTCHAs

VOODOO BEAR demonstrates how this technique can be packaged inside a different lure. In May and June 2026, CrowdStrike Falcon® Complete managed detection and response (MDR) detected likely VOODOO BEAR intrusions affecting employees believed to be Ukrainian at organizations in France, the United States, and Canada.

CrowdStrike Intelligence assesses that VOODOO BEAR almost certainly used ClickFix social engineering to trick users into executing PowerShell commands that downloaded a VBScript payload. In this case, instead of using a fake meeting lure, the adversary compromised Ukrainian websites. Ukrainian visitors to those sites were likely served fake CAPTCHAs.

The details of the lure were different, but the underlying mechanism was the same. The attacker  tricked the user into turning a browser interaction into execution on the endpoint.

How CrowdStrike Stops ClickFix

ClickFix blurs the boundaries between phishing, browser activity, endpoint execution, and identity compromise. Once the victim executes the command, the activity moves into the endpoint. If credentials or tokens are stolen, it can become an identity attack. If the adversary uses those credentials to access SaaS applications, cloud environments, or additional systems, the intrusion expands again.

That progression is part of what makes ClickFix challenging to treat as a single-point security problem. The initial browser interaction is only the beginning of the chain. Each subsequent stage creates a new opportunity for the adversary to establish persistence, steal information, or move further into the environment.

This makes the browser an important control point. With CrowdStrike Falcon® Seraphic® Enterprise Browser, CrowdStrike can extend protection into the browser session where ClickFix begins, while connecting that activity with endpoint, identity, cloud, and SOC telemetry as the attack progresses. 

But it’s not the only capability defending against ClickFix. Here’s how Falcon platform modules disrupt this attack: 

Before execution: Falcon Seraphic Enterprise Browser provides visibility and enforcement inside the browser. This helps identify malicious web behavior and disrupt the copy-and-paste mechanism that ClickFix depends on.

At execution: CrowdStrike Falcon® Prevent and CrowdStrike Falcon® Insight XDR can identify and prevent suspicious PowerShell, VBScript, process, command-line, and other behavioral activity associated with the attack chain.

After initial access: CrowdStrike Falcon® Identity Threat Protection can help detect and stop credential abuse and lateral movement. CrowdStrike Falcon® Next-Gen SIEM can correlate activity across endpoint, identity, browser, cloud, and other telemetry so analysts see a connected intrusion rather than isolated events.

And across the entire environment, CrowdStrike Falcon® Adversary OverWatch™ and Falcon Complete add continuous threat hunting, investigation, containment, and remediation.

The value is defense in depth. If one stage succeeds, the Falcon platform is built to provide additional opportunities to prevent, detect, and respond as the intrusion progresses. 

The Takeaway

Defending against ClickFix therefore requires more than identifying a bad URL or teaching users not to paste commands from websites. Organizations need controls that can disrupt the lure, stop malicious execution, identify credential abuse, connect activity across domains, and respond before initial access becomes a wider compromise.

With Falcon Seraphic Enterprise Browser integrated into the CrowdStrike Falcon® platform, CrowdStrike extends protection to where ClickFix begins: the browser. From the initial browser interaction through endpoint execution and identity abuse, the Falcon platform provides multiple opportunities to break the attack chain before it becomes a breach. 

Additional Resources


CrowdStrike Falcon Platform
Ready to protect your business?

Try CrowdStrike free today

Subscribe

Sign up now to receive the latest notifications and updates from CrowdStrike

See CrowdStrike Falcon in action