ClickFix attacks have rapidly become widespread on both PCs and Macs by tricking users into pasting and executing malicious commands via fake CAPTCHA prompts on compromised websites. This social engineering exploits users' fatigue with complex web interactions, prompting them to unknowingly run malware without the need for traditional code-signing or heavy infrastructure. Security firms have observed ClickFix variants bypassing protections like macOS Gatekeeper, with attackers increasingly leveraging public services and blockchain for control, making this an enduring and challenging threat to mitigate through technology alone.
https://arstechnica.com/security/2026/09/clickfix-attacks-infecting-pcs-and-macs-are-going-viral/
