Copy, Paste, Compromised: How ClickFix Attacks Work and How CrowdStrike Stops Them
CrowdStrike, Tuesday, September 29th, 2026
CrowdStrike explains ClickFix social engineering, where fake errors trick users into pasting malicious commands, and how Falcon stops it.
ClickFix is a social engineering technique that shows victims a fake error, CAPTCHA or repair prompt and instructs them to paste a command into a trusted tool such as the Windows Run dialog, making the user the execution mechanism.
CrowdStrike Intelligence has observed adversaries including STARDUST CHOLLIMA and VOODOO BEAR using ClickFix in real operations, and the CrowdStrike 2026 Global Threat Report recorded a 563% increase in incidents involving fake CAPTCHA lures in 2025.
The post walks through a typical attack chain and describes how the Falcon platform detects and blocks it.