A website asking you to paste a command into Windows Run to prove you are human is a warning to stop. Microsoft Threat Intelligence has documented a ClickFix campaign that hides a malicious script in browser cache before persuading the visitor to execute it.
What you need to know
Do not copy, paste or run commands from a verification page in Run, Terminal or PowerShell. In the campaign Microsoft described, the attacker stages content that looks like a PNG, then relies on the user running a command. Closing the page is preferable to completing those instructions.
Source: Microsoft Threat Intelligence: ClickFix cache campaign
What changed in this attack?
Microsoft’s 3 October thread describes compromised websites fetching a script disguised as an image into the browser’s cached content. A later command locates the staged material and executes it. The deception separates the visible instruction from the larger payload.
This is not a claim that simply viewing an ordinary PNG executes malware. The important step in the reported chain is the visitor being tricked into running attacker-supplied instructions. Microsoft says later stages target browser and device credentials.
Source: Microsoft Threat Intelligence: ClickFix cache campaign
The Australian connection is broader than this campaign
ASD’s Australian Cyber Security Centre warned in May about a separate ClickFix campaign involving compromised WordPress sites and Vidar information-stealing malware. It had observed attacks targeting Australian networks and legitimate Australian business websites being used in the attack chain.
That advisory provides local context, rather than proof that the October cache campaign uses Vidar or has a known Australian victim count. A familiar website name also does not guarantee that every prompt currently displayed on it is trustworthy.
Source: ASD’s ACSC: Australian ClickFix advisory
If you saw the prompt
If you have not run the command, leave the page and do not follow its repair or verification instructions. Keep the browser and operating system updated. The ACSC specifically recommends teaching users to avoid executing commands supplied by websites or pop-ups.
Source: ASD’s ACSC: Australian ClickFix advisory
If you already ran it
Treat the incident as possible malware exposure, even if nothing obvious appeared on screen. For a work computer, tell your IT or security team promptly and follow its incident-response instructions.
Record what happened and when, without running the instructions again.
Follow the ACSC malware recovery guide: ensure antivirus is enabled and updated, disconnect the affected device from networks and external devices, and run a full scan.
Continue through the guide’s recovery steps, including important password changes where appropriate. Seek professional assistance if you are unsure or signs of infection remain.
Source: ASD’s ACSC: recover from malware
Sources and further reading
Microsoft Threat Intelligence: ClickFix cache campaignOriginal 13-post thread: staged PNG-disguised script, fake verification, user execution and final warning.bsky.app
ASD’s ACSC: Australian ClickFix advisorySeparate Australian campaign involving compromised sites and fake CAPTCHAs; prevention guidance.www.cyber.gov.au
ASD’s ACSC: recover from malwareUpdated antivirus, disconnection, full scan, further recovery and professional assistance.www.cyber.gov.au
Spotted something wrong? Corrections are recorded in the open. Report a correction






