ClickFix is a social engineering technique that tricks a user into copying a malicious command from a web page and running it on their own computer. The lure is usually a fake "I'm not a robot" CAPTCHA, a bogus browser error or a phony "fix this problem" pop-up. Instead of clicking a box, the victim is told to press a few keys: open a command window, paste (Ctrl+V) and hit Enter. The page has already placed the attacker's command on the clipboard.
The technique was first observed in October 2023 and has since become one of the most widely used initial-access methods in cybercrime. In September 2026 it hit the headlines again. On August 28, Microsoft disclosed a new variant called TerminalFix, and on September 4 Germany's Federal Office for Information Security (BSI) issued a high-criticality warning after a German state institution was compromised with it. German media have linked the same technique to the August breach of Berlin's Senate administration, which the Rhysida ransomware group claimed along with roughly 5.8 TB of stolen data.
Why does TerminalFix matter? Classic ClickFix sent victims to the Windows Run dialog, which struggles with long commands. TerminalFix instead routes them to Windows Terminal or PowerShell, which run long, multi-stage scripts reliably. The result is no longer a single infected laptop. It is a persistent reverse tunnel that gives attackers a way into the internal network.
For IT managers and CISOs, the lesson is simple: the user is now the delivery mechanism. No malicious attachment is opened and no software vulnerability is exploited, so controls built around blocking downloads and patching flaws never get a chance to fire. Defending against ClickFix takes a mix of endpoint hardening, behavioral detection and 24/7 managed cybersecurity monitoring.
Most security programs are designed around two assumptions: attackers deliver malware as a file, or they exploit an unpatched vulnerability. ClickFix breaks both. The command is typed by a legitimate employee, under their own account, using built-in Windows tools. To many security products, that looks like an administrator doing their job.
That is why the technique has spread so fast. According to researchers, ClickFix lures are often hosted on legitimate websites that were compromised with credentials stolen by infostealer malware. Every new victim can feed the next wave of lures. Fake CAPTCHA overlays imitating Cloudflare verification pages are especially convincing, because employees see real ones every day.
TerminalFix raises the stakes in three ways:
C:\ProgramData and launches a loader tracked as AxolotLoader (also known as LoremIpsumLoader).From there, the playbook is familiar: steal credentials, move sideways, exfiltrate data and then deploy ransomware for double extortion. The BSI confirmed that the attackers attempted exactly that. Organizations that treat a ClickFix infection as "one laptop to reimage" risk missing an intruder who is already inside.
Understanding the attack chain is the fastest way to find where to break it. A typical TerminalFix intrusion follows six steps:
How do you stop it? Each step offers a control point:
ClickFix is not only a technical threat; it is a business risk. A successful intrusion can mean ransomware downtime, regulatory exposure under data protection laws such as Brazil's LGPD or Colombia's Law 1581, and reputational damage that lasts far longer than the outage. A layered defense delivers measurable value:
Why do enterprises need a managed approach? Few in-house IT teams can watch endpoint telemetry around the clock, tune detection rules as variants evolve (ClickFix has already moved from the Run dialog to Terminal, and on macOS to AppleScript) and still keep day-to-day operations running. Combining managed IT services for policy hardening and patching with a SOC that hunts for active threats gives organizations enterprise-grade protection without building it all internally.
HIT Communications has helped enterprises across Latin America, the United States and Europe secure their networks and communications for more than 30 years. Our approach to ClickFix-style attacks combines people, process and technology:
Because HIT operates the network, the security stack and the IT services together, alerts do not fall between vendors. One team sees the full chain, from the web page that delivered the lure to the tunnel that tried to leave your network, and acts on it.
ClickFix and TerminalFix show how modern attackers work in 2026: they do not break in, they ask to be let in. A fake CAPTCHA and one paste were enough to compromise a German state institution and, according to press reports, open the door to one of the year's most visible ransomware attacks on a public administration.
The good news is that this attack chain has clear breaking points. Organizations that restrict script execution, monitor for browser-to-shell behavior, watch outbound tunnels and train employees on this specific lure can stop TerminalFix long before it becomes a ransomware incident.
Three actions to take this week:
Not sure whether your defenses would catch a TerminalFix intrusion? Contact HIT Communications for a security assessment and discover how our managed SOC, IT services and secure connectivity can protect your organization.

Find out how we can transform your business. Talk to one of our experts now!
Get in touch