ClickFix attacks are spreading by infecting Windows and macOS computers through fake CAPTCHAs. Independent researcher Kevin Beaumont said on Reddit that users had lost control of their computers through this method, and stated that attackers had taken over legitimate websites to display fake CAPTCHAs. Users’ desensitization to suspicious instructions due to constant CAPTCHAs, unclosable ads and changing interfaces is increasing the success of the attacks.
The attack usually begins with a CAPTCHA impersonating Cloudflare. Users are instructed to copy a concealed malicious command, paste it into Windows Run, PowerShell or the macOS terminal, and press Enter. The fact that the instructions come from sites that have been in use for years makes it harder for users, particularly those inexperienced in computer security, to become suspicious.
According to BlueVoyant, download portals directed through SEO and supported by malicious advertisements, signing certificates trusted by Microsoft, and constantly changing domain names were needed to distribute the malware previously tracked as Lorem Ipsum. The ClickFix resurgence in late May 2026 eliminated the need for code signing and expanded the pool of victims beyond people searching for Microsoft Teams to anyone visiting compromised websites.
Jamf and a researcher documented macOS versions capable of bypassing Gatekeeper. Cisco Talos reported the use of Google Sheets documents, while Sandworm and Netskope reported the use of blockchain-based smart contracts. Netskope found that 5,400 sites were sending signals to this infrastructure. While BlockBlock and Ublock provide protection, experts recommend raising awareness among inexperienced users.
Why it matters
This development means that the attack has evolved from a campaign targeting a specific application or user group into a broader threat capable of reaching visitors to compromised websites. Eliminating the need for Microsoft-trusted signing certificates removes some of the costs and limitations of the previous distribution chain. The discovery of samples capable of bypassing different defense mechanisms on Windows and macOS shows that security habits specific to a single platform will not be sufficient. The use of channels such as Google Sheets and blockchain smart contracts reveals that users’ trust in familiar services is also an area being exploited. For this reason, it is becoming important for users to recognize the mismatch between a CAPTCHA instruction and the execution of operating system commands, while the extent to which inexperienced people can make this distinction within familiar verification flows remains an open question.
Background
Macs is not a new name in the FikirPilot archive: we published a news story mentioning this name in the past 90 days; that article is dated August 26, 2026.