The security industry keeps raising the bar on authentication, yet the weakest link is still the human — and with ClickFix attacks, hackers have found a way to make people hack themselves.
ClickFix is a social engineering attack where the victim is tricked into running malicious code on their own machine, thus giving the threat actor access to everything, including their saved passwords, passkeys, and session cookies.
A real case study
“Someone recently contacted me with a simple question: ‘Is my computer infected?’ For the record, he’s not a NordPass user — he found me through my personal website. He’d come across a LinkedIn post about ClickFix attacks and realized that, just a week earlier, he’d probably fallen victim to one himself. He was right. His story is worth telling — because everything about it looks harmless until the very last second,” says Deividas Ambrazevicius, an engineering manager at NordPass.
The man asking for help was chatting with a former colleague about a week earlier — a real person he knew, with years of message history between them. Or so he thought. This “former colleague” proposed a call, claiming he wanted to talk about work. However, the call failed — no audio — so he said that Microsoft Teams probably needed an update and sent a tidy set of instructions. Where to go, what to copy, where to paste — all neatly prepared. The man followed every step. Then “the colleague” disappeared. And a week later, doubts set in.
Ambrazevicius suggested reaching out to the person in question through another channel — such as LinkedIn. And sure enough, the colleague knew nothing about any of it. His account had been hijacked.
“I extracted the relevant data from the computer and ran a forensic analysis. What I found included both the malicious traces and pieces of the story of how the attack unfolded,” says Ambrazevicius.
- The code was obfuscated at the individual character level, so a simple text search would not find it.
- It was launched using Invoke-Expression, without ever saving an executable file to the disk. That’s why the traditional antivirus software didn’t react.
- Curl.exe sent the data out over port 443 to a remote command-and-control server (C2).
- All session cookies saved in the Chrome browser were exfiltrated, along with files belonging to several different companies.
- The standard Windows firewall allows all outbound traffic without any warning by default — so the attack went unnoticed in real time.
He adds that after a week far less data remained than there could have been. The best course of action, according to the expert, would have been to immediately disconnect from the internet, but not shut down the computer so the RAM wouldn’t get wiped — that’s how most of the picture gets recovered.
Fake CAPTCHA
According to Ambrazevicius, this was quite a sophisticated attack, involving a hijacked account and a degree of prior preparation. But there are simpler attacks. One of them is fake CAPTCHA — one of the most common ways a ClickFix attack is delivered.
Instead of asking the user to solve an image puzzle, the fake CAPTCHA claims that additional verification steps are required and instructs the user to press a quick sequence of keys. Frequently, that’s Windows Key + R (which opens the Windows native “Run” dialog box), then Ctrl + V (which pastes the hidden malicious payload from the clipboard), and then “Enter” (which executes the command).
“Don’t forget that infostealers don’t just steal passwords — they steal session cookies, the key a server issues after a successful login with 2FA. The criminal loads it into their own browser and opens the account — no password, no code needed. That’s why changing your password after an incident isn’t enough. You need to forcibly terminate all sessions,” Ambrazevicius cautions.
How to avoid falling victim
- If someone tells you that you need to update an app because they can’t hear you — that’s a red flag. Contact the person through a different channel.
- Be extremely cautious if a website or program unexpectedly asks you to paste text or run commands in PowerShell or Terminal.
- A familiar name does not equal a familiar person. Accounts get stolen every day.
- These days, even if you see or hear someone you know, there’s no guarantee it’s really them — it might be a deepfake. Always exercise caution and agree on a code word that only your family and friends know — and ask for it if things feel suspicious.
- If you work with sensitive data and suspect such an incident, do not delay — contact a professional. A computer can reveal a great deal, but only until the user unwittingly destroys the evidence.
- If something like this happens and the sessions and files on your machine are confidential, they must be treated as compromised.
ABOUT NORDPASS
NordPass is a password manager for both business and consumer clients. It’s powered by the latest technology for the utmost security. Developed with affordability, simplicity, and ease of use in mind, NordPass allows users to access passwords securely on desktops, mobile devices, and browsers. All passwords are encrypted on the device, so only the user can access them. NordPass was created by the experts behind NordVPN — the advanced security and privacy app. For more information: nordpass.com.
Related
This entry was posted on September 23, 2026 at 8:47 am and is filed under Commentary with tags Nordpass. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Guest Post: “ClickFix” — a new wave of social engineering
The security industry keeps raising the bar on authentication, yet the weakest link is still the human — and with ClickFix attacks, hackers have found a way to make people hack themselves.
ClickFix is a social engineering attack where the victim is tricked into running malicious code on their own machine, thus giving the threat actor access to everything, including their saved passwords, passkeys, and session cookies.
A real case study
“Someone recently contacted me with a simple question: ‘Is my computer infected?’ For the record, he’s not a NordPass user — he found me through my personal website. He’d come across a LinkedIn post about ClickFix attacks and realized that, just a week earlier, he’d probably fallen victim to one himself. He was right. His story is worth telling — because everything about it looks harmless until the very last second,” says Deividas Ambrazevicius, an engineering manager at NordPass.
The man asking for help was chatting with a former colleague about a week earlier — a real person he knew, with years of message history between them. Or so he thought. This “former colleague” proposed a call, claiming he wanted to talk about work. However, the call failed — no audio — so he said that Microsoft Teams probably needed an update and sent a tidy set of instructions. Where to go, what to copy, where to paste — all neatly prepared. The man followed every step. Then “the colleague” disappeared. And a week later, doubts set in.
Ambrazevicius suggested reaching out to the person in question through another channel — such as LinkedIn. And sure enough, the colleague knew nothing about any of it. His account had been hijacked.
“I extracted the relevant data from the computer and ran a forensic analysis. What I found included both the malicious traces and pieces of the story of how the attack unfolded,” says Ambrazevicius.
He adds that after a week far less data remained than there could have been. The best course of action, according to the expert, would have been to immediately disconnect from the internet, but not shut down the computer so the RAM wouldn’t get wiped — that’s how most of the picture gets recovered.
Fake CAPTCHA
According to Ambrazevicius, this was quite a sophisticated attack, involving a hijacked account and a degree of prior preparation. But there are simpler attacks. One of them is fake CAPTCHA — one of the most common ways a ClickFix attack is delivered.
Instead of asking the user to solve an image puzzle, the fake CAPTCHA claims that additional verification steps are required and instructs the user to press a quick sequence of keys. Frequently, that’s Windows Key + R (which opens the Windows native “Run” dialog box), then Ctrl + V (which pastes the hidden malicious payload from the clipboard), and then “Enter” (which executes the command).
“Don’t forget that infostealers don’t just steal passwords — they steal session cookies, the key a server issues after a successful login with 2FA. The criminal loads it into their own browser and opens the account — no password, no code needed. That’s why changing your password after an incident isn’t enough. You need to forcibly terminate all sessions,” Ambrazevicius cautions.
How to avoid falling victim
ABOUT NORDPASS
NordPass is a password manager for both business and consumer clients. It’s powered by the latest technology for the utmost security. Developed with affordability, simplicity, and ease of use in mind, NordPass allows users to access passwords securely on desktops, mobile devices, and browsers. All passwords are encrypted on the device, so only the user can access them. NordPass was created by the experts behind NordVPN — the advanced security and privacy app. For more information: nordpass.com.
Share this:
Like this:
Related
This entry was posted on September 23, 2026 at 8:47 am and is filed under Commentary with tags Nordpass. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.