• News/
  • https://www.bleepingcomputer.com/news/security/clickfix-malware-attacks-evolve-with-multi-os-support-video-tutorials/

ClickFix malware attacks evolve with multi-OS support, video tutorials

BleepingComputer
·
Bill Toulas
·
Published Nov 6, 2025
·
Updated

ClickFix attacks have evolved to feature videos that guide victims through the self-infection process, a timer to pressure targets into taking risky actions, and automatic  detection of the operating system to provide the correct commands. In a typical ClickFix attack, the threat actor relies on social-engineering to trick users into pasting and executing code or commands from a malicious page. The lures used may vary from identity verification to software problem solutions. The goal is to make the target execute malware that fetches and launches a payload, usually an information stealer. Most of the times, these attacks provided text instructions on a web page but newer versions rely on an embedded video to make the attack less suspicious. Push Security researchers have spotted this change in recent ClickFix campaigns, where a fake Cloudflare CAPTCHA verification challenge detected the victim’s OS and loaded a video tutorial on how to paste and run the malicious commands. Through a JavaScript, the threat actor can hide the commands and copy them automatically into the user's clipboard, thus reducing the chances of human error. On the same window, the challenge included a one-minute countdown timer that presses the victim into taking quick action and leaving little time to verify the authenticity or safety of the verification process. Adding to the deception is a “users verified in the last hour” counter, making the window appear as part of a legitimate Cloudflare bot check ...

Read full article

Affected Software

1 affected component
Cloudflare CAPTCHA
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the evolution of ClickFix malware attacks that now include multi-OS support and video tutorials for self-infection.

2

What security implications are discussed?

The article highlights the dangers of ClickFix malware, including its tactics to manipulate victims into infecting their own systems.

3

What products or software are affected?

The article mentions that Cloudflare CAPTCHA is one of the affected products in relation to ClickFix malware.

4

How do the attacks pressure victims into action?

The ClickFix attacks utilize a timer to create urgency, compelling victims to take risky actions quickly.

5

What new features have been introduced in ClickFix malware?

The malware now has capabilities like automatic OS detection and guided video tutorials that assist in the infection process.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203