惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
aimingoo的专栏
aimingoo的专栏
Martin Fowler
Martin Fowler
C
Check Point Blog
G
Google Developers Blog
V
Visual Studio Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
有赞技术团队
有赞技术团队
MongoDB | Blog
MongoDB | Blog
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
D
Docker
Hugging Face - Blog
Hugging Face - Blog
The GitHub Blog
The GitHub Blog
博客园 - 三生石上(FineUI控件)
A
About on SuperTechFans
Recent Announcements
Recent Announcements
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
阮一峰的网络日志
阮一峰的网络日志
Stack Overflow Blog
Stack Overflow Blog
Vercel News
Vercel News

Check Point Blog

Reading the Signals in the OWASP LLM Top 10 2026 - Check Point Blog Ransomware Didn't Slow Down in Q2 2026. It Just Spread Out. - Check Point Blog July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens - Check Point Blog State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam Native AI Security Comes to Claude: Why Anthropic's Inference Hooks Matter - Check Point Blog Claude AI Security: How Anthropic Inference Hooks Enable Real-Time Protection The Top Exposure Management Questions Security Leaders Ask (Part 1) - Check Point Blog Black Hat 2026: Check Point Research Takes the Stage - Check Point Blog Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security - Check Point Blog Three AI security disclosures, fourteen days: what the warnings signs are telling us - Check Point Blog When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context - Check Point Blog Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance - Check Point Blog Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms - Check Point Blog AI Escaped a Sandbox. That is Not What Should Worry You - Check Point Blog Introducing the Industry's First AI Network Firewall - Check Point Blog Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon - Check Point Blog AI Agent Security Just Had Its Catalyst Moment - Check Point Blog Your AI Governance Policy Should Survive Your Next Model Change - Check Point Blog The Branding and Attribution Behind Cybercrime - Check Point Blog Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report - Check Point Blog Security Advisory - Action Required - July 2026 Security Update - Check Point Blog What the 2026 Exposure Gap Report Reveals About Remediation - Check Point Blog Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention - Check Point Blog The State of Hybrid SASE: Built-In vs. Bolted-On - Check Point Blog AI Appreciation Day: Let's Be Honest About What We're Appreciating - Check Point Blog AI Security Is Never Finished: Building the Continuous Red Teaming Loop  - Check Point Blog AI Security Threats in 2026: Annual Insights from Check Point Research - Check Point Blog AI Agents are Only As Effective as Their Harness - Check Point Blog Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security - Check Point Blog How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox - Check Point Blog Redefining the CISO Contract: From Securing the Business to Securely Doing Business - Check Point Blog
ClickFix: The Attack That Turns Users Into Their Own Atta...
lizwu@checkpoint.com · 2026-06-25 · via Check Point Blog

ClickFix has quickly become one of the most prevalent social engineering techniques on the web. The attack flips a familiar security assumption on its head: instead of slipping a malicious file past endpoint defenses, the attacker convinces the victim to run the payload themselves. No exploit. No malicious attachment. Just a user, a clipboard, and a convincing prompt.

To address this growing threat, the ThreatCloud AI team built a new detection engine, now integrated into Check Point’s Gateways (Zero-Phishing Blade), Email Security and Browse Security.

The ClickFix Threat

ClickFix attacks open with a familiar-looking prompt, a fake CAPTCHA, a Cloudflare verification screen, or a “browser update required” notice. The lure is convincing because it borrows the visual language of real security checks. The pattern is always the same: the victim is presented with a convincing prompt that requires them to take a few steps on their computer to “fix” something. Those steps end with the victim opening the Windows Run dialog, pasting a command from their clipboard, and hitting Enter.

What makes this so effective is that no exploit is involved, the user runs the payload themselves. Endpoint protection tools see a command launched by explorer.exe after a manual paste, a pattern that looks indistinguishable from legitimate user activity. 

Attackers deliver ClickFix through two main methods. Some create dedicated sites impersonating known brands or generic verification pages. Because the domain has no history, traditional reputation systems sometimes catch it, but only after the campaign has run for a while and signals accumulate.
Others compromise legitimate, trusted websites and inject a ClickFix overlay. In those cases, the domain is years old, has a clean reputation, and serves real content alongside the attack. Reputation-based defenses see nothing wrong, and most traditional defenses miss it. 

In both cases, catching ClickFix requires looking at the page itself, at the behavioral indicators of the attack, independently of where it is hosted. 

Introducing the ClickFix Engine 

The ClickFix Engine is a multi-layered AI detection system that analyzes web pages for the behavioral fingerprint of a ClickFix attack. It analyzes the page’s HTML for behavioral signals: fake verification prompts, “open terminal” instructions, clipboard copy APIs, and more. 

The engine operates in multiple stages. After analyzing the behavioral patterns, a deeper AI inspection layer analyzes the full-page content and identifies social engineering tactics. The result is consistent detection regardless of the host domain reputation or use of evasion techniques. Here’s what that looks like in practice. 

Case Study 1 – Tax-Season Impersonation Campaign 

In April 2026, the engine detected a coordinated campaign of five newly registered domains, all registered within the same week, all branded as “Pacific Crest Tax Advisors”. The timing was deliberate, the campaign launched in the U.S. tax filing period, exploiting a time when IRS impersonation scams are at their peak. 

The ClickFix page prompted victims to complete a “verification step”, which silently copied a multi-stage PowerShell payload to their clipboard. Pasting and running it, as the page instructed, would trigger a chain of actions: first downloading a malicious file from a trusted content delivery service, then installing it silently on the machine. The command was deliberately disguised to bypass security scanners, both using a well-known URL to download the malicious file, and the command was splitting its instructions across multiple variables to evade signature-based detection.  

The ClickFix Engine caught all five domains on day zero, before any reputation signals had accumulated!  

Case Study 2 – Catching ClickFix on a Trusted Website 

The second case tells a different story. Same attack, very different infrastructure. In April 2026, the engine flagged two unrelated French websites: vertsport.com, a sportswear retailer active since 2007, and materlo.com, a PrestaShop shop selling automotive tools. Both had clean reputations, valid SSL certificates, and years of legitimate activity. Nothing about either site would raise a flag. 

Both had been quietly hijacked. Hidden inside their product and blog pages was a fake Cloudflare verification prompt, identical on both sites, pointing to the same attacker-controlled server. Visitors who followed the “verification” steps would unknowingly run a payload that disabled Windows Defender and installed malware disguised as WebRTC driver, all while browsing what looked like a perfectly normal website. 

Because the engine inspects the behavior of the page rather than the reputation of the domain, it flagged both sites. The engine analyzed the page’s HTML and detected multiple behavioral signals characteristic of a ClickFix attack: a fake verification prompt, clipboard copy instructions, and system command execution patterns. With enough signals matching simultaneously, it returned a high-confidence malicious verdict, regardless of how trusted the hosting domain was. 

Preventing ClickFix Going Forward 

ClickFix is evolving fast. We have already detected coordinated campaigns impersonating trusted brands, compromised well-known legitimate websites, and new lure variants designed specifically to bypass traditional defenses. Attackers are investing heavily in making these pages look more convincing and harder to detect. 

The ClickFix Engine evolves with the attack. Because it inspects the behavioral fingerprint of the page rather than any single static feature, new lures and obfuscation techniques get caught regardless of how the attack is dressed up.