Fake CAPTCHA verification prompt used in a ClickFix malware scam

“I'm Not a Robot” — The New Scam That Gets Employees to Hack Themselves

Picture an employee searching for a piece of software, clicking a normal-looking ad, and landing on a page with a familiar “Verify you're human” checkbox. They click it. Nothing suspicious happens: no download, no pop-up. Just a short list of instructions: press two keys, paste, hit enter. It looks exactly like the CAPTCHA prompts everyone sees a dozen times a day. Except this one just installed malware on their computer, and they did it themselves, with their own hands, on your company's device.

This technique has a name — ClickFix—, and it's exploded over the past year. According to research from ESET, ClickFix attacks surged 517% in a six-month period and now account for nearly8% of all blocked attacks, making it the second most common attack vector in the world, trailing only phishing itself.

How the scam actually works

ClickFix doesn't rely on tricking someone into downloading a file, which is the thing most employee security training focuses on. Instead, it walks the victim through installing malware step by step, disguised as routine troubleshooting:

1.    The victim lands on a page often via a malicious ad, a fake software download site, or a compromised legitimate site that presents what looks like a standard CAPTCHA or “verifyyou're human” check.

2.    Clicking the button secretly copies a malicious command to the victim's clipboard. The victim never sees this happen.

3.    The page then displays simple instructions: open the Windows Run dialog (Win+R) or a Mac Terminal, paste, and press Enter.

4.    Because this looks like routine technical troubleshooting rather than an obvious download, most people follow along without a second thought.

5.    The moment Enter is pressed, the command runs silently in the background. No alert, no install wizard, no obvious warning sign just an infected machine.

From there, the payload is typically an infostealer that scrapes saved passwords, browser cookies, autofill data, and cryptocurrency wallets, feeding directly into the same kind of account and session hijacking we covered in our last post on AI account security.

This just happened at a household name

This isn't a theoretical risk. Just this week, attackers hijacked HBO Max's own official Reddit account and used it to run malicious ads promoting a fake HBO Max app for Mac. Anyone who clicked was sent to a convincing lookalike site and instructed to open Terminal and paste a command to “install the software.” Instead, victims installed real malware credential-stealing tools on macOS, infostealers and crypto-theft malware on Windows. If a recognized, verified brand account can be hijacked to run this exact playbook, any employee can encounter a version of it on an ordinary afternoon of browsing.

Why this scam works so well

Traditional phishing training tells employees to watch for suspicious downloads, sketchy attachments, and links that don't match the sender. ClickFix sidesteps all of that. There's no file to download and no attachment to open; the victim is the one who runs the command, which makes it feel more like solving a minor technical hiccup than falling for an attack. It also specifically exploits the instinct to just “fix it yourself” rather than bothering IT with something that looks routine.

What to teach your team

•      A real CAPTCHA never leaves your browser. No legitimate verification process will ever ask you to open the Run dialog, Terminal, PowerShell, or any system tool.

•      If a webpage asks you to paste and run something, stop. Close the tab. Don't paste unfamiliar content into any system tool, even if the instructions sound routine.

•      Clear your clipboard after closing a suspicious page. Copy any harmless piece of text to overwrite whatever was silently placed there.

•      Report it; don't just close the tab and move on. A single ClickFix ad or lookalike page usually means others in your organization are being targeted with the same campaign.

•      Treat “verify you're human” fatigue as a real risk. Employees see so many CAPTCHAs that they're primed to click through without thinking, which is exactly what this attack is built to exploit.

How Cynergy Information Technology can help

Attacks like ClickFix are designed to slip past the instincts your team has already been trained on, which means security awareness training has to evolve just as fast as the attacks do. Cynergy Information Technology can help you run up-to-date phishing and social engineering training that covers exactly these tactics, put endpoint protection in place that can catch these payloads even when an employee is tricked into running them, and build a culture where employees report a strange prompt instead of quietly clicking through it. Reach out to Cynergy IT to talk about where your team's training stands today.