ClickFix is a social engineering technique where a fraudulent site simulates a technical error and instructs the user to press Windows+R, paste a command, and hit Enter. That command, silently placed on the clipboard without the victim ever copying it, installs malware directly, skipping any downloaded file an antivirus could inspect.
The malicious page runs JavaScript that writes to the clipboard the moment the user clicks a fake "human verification" button. The user never selected or copied that text — they only paste and run it.
Why EDR doesn't stop it
The commands invoke legitimate, signed Windows binaries (powershell.exe, mshta.exe, curl.exe) that any EDR must allow to keep the system functioning, making the attack hard to distinguish from a real admin action.
Talk to Blurtek about hardening your team against ClickFix-style attacks.
Solicitar diagnóstico