Skip to content

ClickFix: when the user runs the attack

ClickFix does not ask employees to open a malicious attachment. It guides them through what looks like a routine repair or verification step until they execute the attack themselves. Here is how to build a ClickFix simulation in Cyberdise Awareness — from scenario selection to delivery and measurement.

A man at a standing desk in a bright office pauses with his hands lifted away from the keyboard, hesitating in front of a dialog box on his monitor
In this article

Cybercriminals have become remarkably good at bypassing technical security controls. Rather than exploiting software vulnerabilities, many modern attacks exploit something much easier: human behavior.

One of the fastest-growing examples is ClickFix. Instead of asking users to click a malicious attachment, attackers guide them through what appears to be a legitimate troubleshooting or verification process. The victim ultimately executes the malicious action themselves. Traditional phishing exercises are still valuable, but they no longer cover the full spectrum of modern social engineering.

What is ClickFix?

ClickFix is a social engineering technique in which attackers convince users to perform technical actions that ultimately compromise their own systems. Unlike traditional phishing, it usually does not rely on a malicious attachment or an exploit. Instead, users are presented with what appears to be a legitimate verification step: “Verify you’re human”, “Repair your Microsoft 365 document”, “Update your SAP security component”, “Fix your browser security module”.

The instructions appear routine and often resemble the kind of technical guidance users have seen before. Victims are typically asked to:

  • press Win + R
  • paste a command
  • execute PowerShell
  • run a verification command
  • install a “required” component

Once executed, malware, credential stealers or remote access tools are downloaded and installed. The important observation is that the user performs the critical action voluntarily: from the operating system’s perspective nothing suspicious happened — the user simply followed instructions.

A typical workflow: attackers lure users to a fake website through email, vishing, SEO poisoning or other channels. The site displays convincing technical instructions, the user follows them, executes the supplied command, and malware reaches the endpoint.

Why ClickFix simulations matter

Modern social engineering no longer consists solely of phishing emails. Attackers combine email, voice calls, messaging applications, malicious advertisements and compromised websites — and they have shifted from simple link-clicking attacks to interaction-driven attacks that require the victim to actively perform technical actions.

Most employees already know they should avoid clicking suspicious links. ClickFix bypasses that knowledge: instead of asking users to trust a suspicious email, attackers ask them to trust what appears to be a legitimate IT support workflow. The victim believes they are fixing Microsoft Office, repairing a browser issue, updating SAP, restoring a VPN session or opening a protected document. The attacker embeds malicious instructions inside a believable business process.

This is why a ClickFix simulation is becoming an important addition to traditional phishing simulations: it shows whether employees recognize suspicious technical instructions, not merely suspicious emails. Security awareness is no longer just about recognizing suspicious messages — employees need to recognize suspicious processes and workflows.

Common ClickFix scenarios

Although the classic fake CAPTCHA remains common, attackers increasingly target enterprise applications that employees use every day.

Fake CAPTCHA“Verify you’re human.” The user is instructed to execute a malicious PowerShell command.
Microsoft 365 document repair“This document cannot be rendered securely.” Running the suggested repair command installs a credential stealer or a remote access trojan.
SAP Secure Login“Your security component is outdated.” A fake verification command executes malware before the SAP session starts.
Salesforce session verification“Refresh your browser security module.” The attacker steals session cookies or authentication tokens.
VPN portal“Certificate validation failed.” The user is tricked into compromising their own endpoint.
SharePoint“Protected document viewer requires activation.” The fake activation process leads to credential theft.

Creating a ClickFix simulation in Cyberdise Awareness

Cyberdise Awareness allows organizations to create realiztic ClickFix simulations that reflect their own environment and business applications. The process is straightforward.

  1. 01Create the campaignCreate a phishing simulation as you normally would and select the target recipient group.
  2. 02Choose a realiztic scenarioSelect a ClickFix scenario that resembles a workflow your employees actually encounter. The more closely the exercise reflects everyday work, the more meaningful the behavioral observations.
  3. 03Build the landing pageThe Cyberdise Website Cloner transforms existing web pages into realiztic landing pages that closely resemble legitimate business portals. The cloned content is then customized for the exercise.
  4. 04Select the delivery methodCyberdise supports both delivery approaches commonly observed in real-world ClickFix campaigns.

Option 1 — URL delivery

The email, or the landing page behind it, contains ‘only’ a link. Users are directed to the simulation landing page (index.html), where the ClickFix dialogue is displayed. To measure interaction, the copied command is implemented as a hyperlink pointing to the success page (account.html): when users click Copy, they are redirected there and the simulation records a successful completion. This reflects many current ClickFix attacks, where the malicious workflow is hosted entirely on an external website.

Option 2 — HTML attachment delivery

Alternatively, the phishing email carries an HTML attachment instead of a link. When opened, the file renders the fake ClickFix page locally in the user’s browser; Cyberdise supports these exercises through its File Based Attachment functionality. It mirrors real-world campaigns that deliver the landing page as an attachment rather than through a URL — and opening or downloading the file is itself a clearly measurable success event.

Behavioral Defense Engineering in practice

ClickFix demonstrates how quickly social engineering techniques evolve. Employees are no longer simply asked to click links — they are persuaded to execute technical procedures that appear completely legitimate. Preparing users for that requires more than conventional phishing simulations.

Behavioral Defense Engineering focuses on improving defensive behavior by exposing employees to realiztic attack workflows before they encounter them in production. ClickFix exercises complement traditional phishing campaigns by helping employees recognize manipulation embedded within everyday business processes rather than just suspicious emails.

The effectiveness of ClickFix lies not in exploiting software vulnerabilities but in exploiting trust, routine and human behavior. Organizations that rely solely on traditional, standardized phishing simulations risk leaving an important attack vector unaddressed. As attackers innovate, defensive behavior must evolve just as quickly.

What is a ClickFix simulation?
A simulated ClickFix attack, used in security awareness training. It presents a fake but realiztic technical prompt — a “document repair” or “verification” step — and measures whether employees follow the instructions, without triggering any real compromise.
How does it differ from a standard phishing simulation?
A phishing simulation tests whether a user clicks a link or opens an attachment. A ClickFix simulation tests whether they will actively execute a technical action — opening the Windows Run dialog, pasting a command — after being guided through what looks like legitimate troubleshooting.
What makes ClickFix attacks hard to detect technically?
The user opens the dialog and runs the command themselves, so the operating system sees an intentional, user-initiated task rather than an exploit or a malicious attachment. That bypasses many controls built to detect malicious links, attachments or automated exploitation.
Can ClickFix simulations be delivered as an HTML attachment instead of a link?
Yes. Cyberdise supports URL-based delivery with an externally hosted landing page, and File Based Attachment delivery, where the page renders locally when the employee opens an HTML file.

Run a ClickFix exercise before your attackers do.

Book a DemoDownload

Sources

  1. How to Create a ClickFix Simulation with Cyberdise Behavioral Defense EngineeringCyberdise AG
  2. 2026 Cyber Security ReportCheck Point

Written by

Palo Stacho

Founder and Managing Director

Founder and Managing Director of Cyberdise AG in Zug, Switzerland. He writes about the state of the awareness industry and why behavior, not knowledge, decides whether an attack succeeds.