ClickFix attacks trick Mac and Windows users into self-hacking

Λογισμικό

A rising cybersecurity threat known as «ClickFix» is rapidly evolving, using deceptive tactics and compromised ad accounts on major platforms like Reddit to trick individuals into compromising their own computers. The technique relies on convincing victims that they are completing a simple verification step.

Instead of a standard malware download, the attacks display fake CAPTCHA or anti-bot prompts instructing users to copy and paste specific text strings into the Windows Command Prompt or macOS Terminal. Once executed, info-stealing malware is instantly installed, bypassing traditional antivirus tools because the user interacted directly with the operating system.

Security experts emphasize that while developers routinely use system consoles, everyday users should remain extremely cautious about executing terminal commands found online. Organizations and platforms are under increasing pressure to secure advertising channels and restrict unnecessary access to core system utilities.

  • ClickFix campaigns trick users into executing malicious terminal commands themselves.
  • Attackers recently leveraged compromised ad accounts on platforms like Reddit.
  • Malware bypasses standard antivirus by exploiting native OS command lines.
  • Users are urged to avoid pasting unknown code into Windows Prompt or Mac Terminal.

Sources:

Leave a Reply

Your email address will not be published. Required fields are marked *