Threat Intelligence

Why Hackers Are Choosing Simplicity Over Sophistication: The Rise of 'ClickFix' Attacks

The Hacker News · 1 Sept 2026
Key Takeaway Train staff to be suspicious of any website instructing them to copy and paste commands into a terminal, no matter how official it looks.

Cybercriminals aren't always chasing cutting-edge exploits — often, they just want something that works reliably, again and again. According to Microsoft's threat intelligence team, the most common way attackers broke into organisations last year wasn't a sophisticated hack, but a simple trick called ClickFix.

Here's how it works: a fake webpage asks visitors to complete a routine 'prove you're not a robot' check. While the person is distracted reading instructions, the page secretly copies a malicious command to their clipboard. The site then guides the unsuspecting user to open a terminal window on their computer and paste it in — effectively tricking them into running the attacker's code themselves. No advanced malware or technical exploit is required; it simply relies on people following instructions without questioning them.

This approach highlights a broader trend: attackers favour techniques that are cheap, easy to repeat, and don't require deep technical skill. Because ClickFix relies on human behaviour rather than software flaws, traditional security tools may not catch it every time. Awareness and scepticism are the best defences.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.