The verification prompt that tells you to open Run
Somebody on your team is browsing a normal-looking website and a box pops up: "verify you are human" or "there was a problem loading this page, click to fix it." It asks them to click a button, and a short set of instructions appears. Press two keys together, paste, press enter. It looks exactly like the kind of routine check everyone has clicked through a hundred times without thinking.
Except this time, the thing they paste is not a verification code. It is a command that installs malware, and they typed it in themselves.
This technique has a name, ClickFix, and it has become one of the most common ways attackers get malware onto a device. It works because it breaks the one rule most staff training actually covers: don't open attachments, don't download files. ClickFix asks for neither. Nothing is downloaded, nothing is opened, and it now works against both Windows and Mac computers, which is why it is worth a few minutes with your team this week.
How the trick actually works
The lure varies. Sometimes it is a fake CAPTCHA (the "I am not a robot" checkbox sites use to block automated bots). Sometimes it is a fake error message dressed up to look like it came from the browser or a video call tool such as Google Meet. Sometimes it is a fake software update prompt. Malwarebytes has tracked versions posing as a Mac disk cleanup tool, complete with a fake "24.7 GB freed" confirmation to sell the con, and Microsoft has documented lures spoofing Cloudflare's own verification checks.
Whatever the disguise, the instruction that follows is the same shape. On Windows, the page tells the visitor to press the Windows key and R together, which opens the Run dialog (a small box built into Windows for typing a command directly, rather than clicking an icon), then paste and press enter. On a Mac, the page directs the visitor to open Terminal (the Mac's equivalent command-typing tool) and do the same. A script on the malicious page has already copied the real command to the clipboard the moment the visitor clicked "verify." The visitor never reads what they are pasting. They just follow the steps, because the steps look procedural rather than dangerous.
What runs next is usually a stealer: malware built to quietly harvest saved passwords, browser cookies, and any cryptocurrency wallets on the device, then hand them to the attacker. Microsoft has tracked campaigns using this technique against thousands of devices a day since early 2026, and Malwarebytes reports that ClickFix was behind more than half of all malware delivered this way in 2025.
Why the usual training does not cover it
Most phishing training boils down to one instruction: do not click links, do not open attachments from people or sites you do not trust. ClickFix does not ask anyone to open anything. There is no file to scan, nothing for an email filter to catch, no download for antivirus software to inspect before it runs. The malicious step is the user typing a command into a tool that is meant to be typed into, and to a spam filter or a browser's built-in protections, that looks like nothing happened at all.
What to do
Tell staff one plain rule. No genuine CAPTCHA, browser update, or error message ever asks you to open Run or Terminal and paste something in. If a website tells you to do that, close the tab. There is nothing to fix.
Give IT a specific thing to check. Review antivirus or endpoint logs from the past month for anything flagged as a stealer, particularly on machines where someone recalls an unusual "verify" or "fix this" popup. If you use Microsoft 365 or a similar admin console, check whether PowerShell execution logging is switched on for your Windows machines: it is one of the more useful signals for catching this pattern after the fact.
Put it on this week's list, not next quarter's. This belongs in a five-minute team message or the next stand-up, not a formal training session. The instruction is short enough to say once and have it stick.
How Steelwise can help
If you want a second opinion on whether your staff security training actually covers techniques like this one, or want your endpoint logging checked for the gaps ClickFix exploits, that is a conversation worth having. Get in touch.