Cybercriminals have become remarkably good at bypassing technical security controls. Rather than exploiting software vulnerabilities, many modern attacks exploit something much easier: human behavior.
One of the fastest-growing examples is ClickFix. Instead of asking users to click a malicious attachment, attackers guide them through what appears to be a legitimate troubleshooting or verification process. The victim ultimately executes the malicious action themselves. Traditional phishing exercises are still valuable, but they no longer cover the full spectrum of modern social engineering.
What is ClickFix?
ClickFix is a social engineering technique in which attackers convince users to perform technical actions that ultimately compromise their own systems. Unlike traditional phishing, it usually does not rely on a malicious attachment or an exploit. Instead, users are presented with what appears to be a legitimate verification step: “Verify you’re human”, “Repair your Microsoft 365 document”, “Update your SAP security component”, “Fix your browser security module”.
The instructions appear routine and often resemble the kind of technical guidance users have seen before. Victims are typically asked to:
- press
Win + R - paste a command
- execute PowerShell
- run a verification command
- install a “required” component
Once executed, malware, credential stealers or remote access tools are downloaded and installed. The important observation is that the user performs the critical action voluntarily: from the operating system’s perspective nothing suspicious happened — the user simply followed instructions.
A typical workflow: attackers lure users to a fake website through email, vishing, SEO poisoning or other channels. The site displays convincing technical instructions, the user follows them, executes the supplied command, and malware reaches the endpoint.
Why ClickFix simulations matter
Modern social engineering no longer consists solely of phishing emails. Attackers combine email, voice calls, messaging applications, malicious advertisements and compromised websites — and they have shifted from simple link-clicking attacks to interaction-driven attacks that require the victim to actively perform technical actions.
Most employees already know they should avoid clicking suspicious links. ClickFix bypasses that knowledge: instead of asking users to trust a suspicious email, attackers ask them to trust what appears to be a legitimate IT support workflow. The victim believes they are fixing Microsoft Office, repairing a browser issue, updating SAP, restoring a VPN session or opening a protected document. The attacker embeds malicious instructions inside a believable business process.
This is why a ClickFix simulation is becoming an important addition to traditional phishing simulations: it shows whether employees recognize suspicious technical instructions, not merely suspicious emails. Security awareness is no longer just about recognizing suspicious messages — employees need to recognize suspicious processes and workflows.
Common ClickFix scenarios
Although the classic fake CAPTCHA remains common, attackers increasingly target enterprise applications that employees use every day.
Creating a ClickFix simulation in Cyberdise Awareness
Cyberdise Awareness allows organizations to create realiztic ClickFix simulations that reflect their own environment and business applications. The process is straightforward.
- 01Create the campaignCreate a phishing simulation as you normally would and select the target recipient group.
- 02Choose a realiztic scenarioSelect a ClickFix scenario that resembles a workflow your employees actually encounter. The more closely the exercise reflects everyday work, the more meaningful the behavioral observations.
- 03Build the landing pageThe Cyberdise Website Cloner transforms existing web pages into realiztic landing pages that closely resemble legitimate business portals. The cloned content is then customized for the exercise.
- 04Select the delivery methodCyberdise supports both delivery approaches commonly observed in real-world ClickFix campaigns.
Option 1 — URL delivery
The email, or the landing page behind it, contains ‘only’ a link. Users are directed to the simulation landing page (index.html), where the ClickFix dialogue is displayed. To measure interaction, the copied command is implemented as a hyperlink pointing to the success page (account.html): when users click Copy, they are redirected there and the simulation records a successful completion. This reflects many current ClickFix attacks, where the malicious workflow is hosted entirely on an external website.
Option 2 — HTML attachment delivery
Alternatively, the phishing email carries an HTML attachment instead of a link. When opened, the file renders the fake ClickFix page locally in the user’s browser; Cyberdise supports these exercises through its File Based Attachment functionality. It mirrors real-world campaigns that deliver the landing page as an attachment rather than through a URL — and opening or downloading the file is itself a clearly measurable success event.
Behavioral Defense Engineering in practice
ClickFix demonstrates how quickly social engineering techniques evolve. Employees are no longer simply asked to click links — they are persuaded to execute technical procedures that appear completely legitimate. Preparing users for that requires more than conventional phishing simulations.
Behavioral Defense Engineering focuses on improving defensive behavior by exposing employees to realiztic attack workflows before they encounter them in production. ClickFix exercises complement traditional phishing campaigns by helping employees recognize manipulation embedded within everyday business processes rather than just suspicious emails.
The effectiveness of ClickFix lies not in exploiting software vulnerabilities but in exploiting trust, routine and human behavior. Organizations that rely solely on traditional, standardized phishing simulations risk leaving an important attack vector unaddressed. As attackers innovate, defensive behavior must evolve just as quickly.

