ClickFix attacks infecting PCs and Macs are going viral
ClickFix attacks infecting PCs and Macs are going viral
“ClickFix” 攻击正席卷 PC 和 Mac 电脑
It wasn’t that long ago that ClickFix attacks were exotic. Now the technique has become mainstream as attackers reap its simplicity and effectiveness in infecting users of PCs and Macs alike. All that’s required is a compromised website—a painless enough task—a fake CAPTCHA overlay, and the inclusion of a single terminal command. So many visitors get suckered into pasting and running the command that just about every malware pusher has adopted the technique. Even Kremlin-backed hacking groups are joining in. 不久前,“ClickFix” 攻击还被视为一种罕见的手段。如今,随着攻击者利用其简单且高效的特性来感染 PC 和 Mac 用户,这种技术已成为主流。攻击者只需入侵一个网站(这并非难事),覆盖一个虚假的验证码(CAPTCHA)弹窗,并植入一条终端命令即可。由于大量访客被诱骗去复制并运行这些命令,几乎所有的恶意软件分发者都采用了这种技术,甚至连克里姆林宫支持的黑客组织也参与其中。
“Reddit is becoming post after post after post of people getting their computer infected via ClickFix,” independent researcher Kevin Beaumont observed Thursday. “Legit websites everywhere [are] getting hacked to serve the fake captcha prompts.” 独立研究员凯文·博蒙特(Kevin Beaumont)周四指出:“Reddit 上充斥着用户因 ClickFix 而导致电脑中毒的帖子。到处都是合法的网站被黑,用来展示虚假的验证码提示。”
How many of us make things worse
我们中有多少人在推波助澜?
More seasoned Internet users—a fair number who read this site—are quick to dismiss the attack. They typically blame the people who fall for the scams and marvel at their gullibility and lack of attention. The reality is that for more casual users, using computers and the Internet has become so difficult—think impossible-to-close interstitials, CAPTCHAs with an endless series of pictures to analyze, and constantly changing interfaces that bury the features they’re looking for—that they have grown desensitized to instructions that seem ridiculous and burdensome. 经验丰富的互联网用户(本站的许多读者即属此类)往往会轻视这种攻击。他们通常会责怪那些上当受骗的人,感叹他们的轻信和粗心。但现实情况是,对于普通用户而言,使用电脑和互联网已经变得极其困难——想想那些无法关闭的插页广告、需要分析无数张图片的验证码,以及不断变化、将常用功能隐藏得极深的界面——他们已经对那些看似荒谬且繁琐的操作指令产生了麻木感。
ClickFix attackers are capitalizing on this fatigue. Typically, attacks begin with a simple CAPTCHA image, often masquerading as one from Cloudflare. After engaging with the box, the user sees a line of text, often obscured in a way to mask any malicious commands. Then the user is instructed to copy the text and paste it into the Windows Run, PowerShell, or macOS terminal and click Enter. The instructions come from websites people have used for years. The directions seem no more suspicious than things they’ve been required to do for a decade. Why would someone without a firm grasp of computer security have any reason to hesitate? ClickFix 攻击者正是利用了这种疲劳感。攻击通常始于一张简单的验证码图片,往往伪装成 Cloudflare 的样式。用户与弹窗交互后,会看到一行文字,这些文字通常经过处理以掩盖恶意命令。随后,用户被引导将这段文字复制并粘贴到 Windows 的“运行”窗口、PowerShell 或 macOS 终端中并按下回车键。这些指令来自人们使用多年的网站,看起来并不比他们过去十年中被要求执行的操作更可疑。对于那些缺乏计算机安全知识的人来说,他们有什么理由怀疑呢?
For the people behind the attacks, ClickFix now makes their job much easier. Prior to ClickFix, they would have needed to install the malware (tracked as Lorem Ipsum, security firm BlueVoyant said recently) using resource-intensive infrastructure, including SEO-manipulated and malvertised download portals, Microsoft-trusted signing certificates, and continuously rotated domains for delivering Microsoft Installer packages. 对于幕后黑手来说,ClickFix 让他们的工作变得轻松多了。在 ClickFix 出现之前,他们需要使用资源密集型的基础设施来安装恶意软件(安全公司 BlueVoyant 最近将其追踪为“Lorem Ipsum”),包括通过 SEO 操纵和恶意广告推广的下载门户、微软信任的签名证书,以及不断轮换的域名来分发 Microsoft Installer 安装包。
“The pivot to ClickFix in late May 2026 eliminates the code-signing requirement entirely, substituting the legitimacy of a validly signed installer with a different form of legitimacy: a user voluntarily executing the malicious command in their own terminal,” BlueVoyant said. “[T]he ClickFix model broadens the victim pool from users searching specifically for Microsoft Teams to anyone browsing a browsing a compromised website.” BlueVoyant 表示:“2026 年 5 月下旬转向 ClickFix 后,完全消除了代码签名的需求,用另一种形式的‘合法性’取代了有效签名安装程序的合法性:即用户在自己的终端中自愿执行恶意命令。ClickFix 模式将受害者群体从专门搜索 Microsoft Teams 的用户扩大到了任何浏览受感染网站的人。”
The situation for macOS users isn’t any better. Both Mac security firm Jamf and a researcher have documented macOS variations of ClickFix that can bypass Gatekeeper protections. ClickFix attackers keep finding new ways to use public services—including publicly published Google Sheets documents, according to Cisco Talos. Other attackers, including Russia’s state-sponsored Sandworm, are hosting their control infrastructure in blockchain-based smart contracts. Security firm Netskope recently found another campaign that used the same approach. The security company counted 5,400 sites beaconing to it, an indication of the reach and scope of that campaign. macOS 用户的情况也不容乐观。Mac 安全公司 Jamf 和一位研究人员都记录了 ClickFix 的 macOS 变体,这些变体可以绕过 Gatekeeper 的保护。据思科 Talos 称,ClickFix 攻击者不断寻找利用公共服务的新方法,包括公开发布的 Google 表格文档。其他攻击者,包括俄罗斯国家支持的 Sandworm 组织,正将其控制基础设施托管在基于区块链的智能合约中。安全公司 Netskope 最近发现了另一场使用相同方法的攻击活动。该公司统计到有 5,400 个网站向其发送信号,这显示了该攻击活动的覆盖范围和规模。
And as OS makers and defenders build new defenses, attackers keep finding documented ways to work around them. The upshot of all this is that ClickFix is a highly effective and efficient means of spreading all sorts of malware. It’s not going away, and victim-blaming or shaming only makes the problem worse. 随着操作系统制造商和防御者建立新的防御措施,攻击者不断找到绕过这些措施的方法。这一切的结果是,ClickFix 已成为传播各类恶意软件的一种高效手段。它不会消失,而指责或羞辱受害者只会让问题变得更糟。
There are a fair number of plugins, standalone products, and built-in defenses that are designed to blunt the success of ClickFix attacks. For instance, BlockBlock, the software that monitors Macs for processes that seek to permanently install themselves, can block ClickFix attacks as soon as a user presses the ⌘+V keys. Ublock has been updated to do something similar. Beyond those fixes, those of us with more security training should build awareness with our less experienced neighbors, family members, and friends. The mass adoption of ClickFix demonstrates its success, and it’s not going away any time soon. 目前已有不少插件、独立产品和内置防御措施旨在削弱 ClickFix 攻击的成功率。例如,监控 Mac 上试图永久安装进程的软件 BlockBlock,可以在用户按下 ⌘+V 键时立即阻止 ClickFix 攻击。Ublock 也已更新以实现类似功能。除了这些修复措施外,我们这些受过更多安全培训的人,应该帮助身边经验不足的邻居、家人和朋友建立安全意识。ClickFix 的大规模普及证明了其“成功”,而且它短期内不会消失。