Malware activated using ClickFix technology

The National Cyber Security Centre has highlighted in its weekly letter (week32) that there have been cases of ClickFix infection again in the last few weeks.

With ClickFix, the user is tricked into activating the malware on their device. The technology is based on the fact that users are used to performing tasks like the "Confirm that you are human" and CAPTCHA checks in the context of web browsing. The purpose of the malware may be to extract data from the device (passwords, bank IDs, or other sensitive information) or to activate the ransomware.

Typically, an attack using ClickFix technology begins when a user enters a scam site (e.g., via an email link or a malicious online advertisement) or the user enters a hijacked website. A notice appears on the website instructing the user to take action, for example, to get ahead on the site or to fix a problem. In reality, these measures activate the malware on the user's device. It is a good idea to sound the alarm bells if the instruction prompts you to copy and paste text into the command line of your device.

In accordance with the National Cyber Security Center's instructions, an individual user can protect themselves from ClickFix attack by the following measures:

  • Do not copy and paste text obtained from a web page into your computer's command prompt unless you know exactly what you are doing.
  • Beware of website prompts to open Run or PowerShell windows (command prompt) on your own device.
  • Report suspicious findings to tietoturva@oulu.fi.
Created 11.8.2026 | Updated 11.8.2026