16 min read

Gmail ClickFix Scam 2026: Fake CAPTCHA That Installs Malware

A fake CAPTCHA in your Gmail inbox tells you to paste one command - and the 2026 ClickFix scam installs an infostealer. Here's how to spot and stop it.

OldGmail Team
Gmail ClickFix Scam 2026: Fake CAPTCHA That Installs Malware

You open a link from your Gmail inbox, land on what looks like a routine "Verify you are human" page, and it asks you to do one small thing: press a keyboard shortcut, paste what is already on your clipboard, and hit Enter. It feels like a normal CAPTCHA. It is not. This is the ClickFix scam — the fastest-growing malware delivery trick of 2026, and Gmail is one of its favorite doorways. Google named it directly in its June 2026 fraud advisory, and security firms tracked it expanding across new loaders and fake-update lures through the summer.

The genius of the ClickFix scam is that it never sends you a file to download and never triggers the malware warnings you have been trained to watch for. Instead, it convinces you to run the command yourself. This guide explains exactly how the attack works, how the lure reaches your Gmail inbox, what the pasted command really does, and the simple rule that defeats every version of it. Whether you protect one personal account or manage dozens of aged Gmail accounts for outreach, ClickFix is now a threat you need to recognize on sight.

What Is the ClickFix Scam?

The ClickFix scam is a social-engineering attack that disguises malware installation as a verification or repair step. Instead of tricking you into downloading and running a malicious file — the classic approach that antivirus tools are built to catch — it presents a fake problem and a fake fix. The "fix" is a command the attacker has already copied to your clipboard through the malicious web page. You are told to open a system tool, paste the command, and press Enter. When you do, you run the malware with your own hands, on your own machine, bypassing the browser's download defenses entirely.

The name comes from the pattern: you click to solve a problem, and the page promises to fix it. In practice the overlay usually mimics a familiar security check — a Cloudflare Turnstile challenge, a Google reCAPTCHA box, or a "your browser needs an update to view this content" banner. The disguise matters because these are exactly the interruptions people have learned to click through without thinking. A ClickFix scam weaponizes that reflex. There is no unusual download prompt, no obviously suspicious attachment, and no broken English — just a clean, professional page asking you to complete a step you have completed a hundred times before.

What makes the ClickFix scam so dangerous is that it sidesteps the defenses most people rely on. Modern browsers scan downloads, flag executables, and warn about unknown files. Email providers like Gmail scan attachments and strip dangerous file types. None of that helps when the victim opens a terminal and types the command in themselves. The attack lives in the gap between your security tools and your trust, and that gap is exactly where 2026's most successful campaigns are operating.

Why ClickFix Exploded in 2026

ClickFix techniques existed before 2026, but this was the year they went mainstream. Several forces converged to make the ClickFix scam the delivery method of choice for criminals targeting Gmail and Google accounts.

  • It defeats download-based defenses. Because the victim runs the command manually, there is no file for the browser or email scanner to quarantine. This "living off the land" approach uses tools already on the machine, so nothing looks out of place until it is too late.
  • AI erased the language tells. The old giveaways — misspellings, broken grammar, awkward phrasing — are gone. Generative tools produce flawless, perfectly localized lure pages and emails in seconds, so a ClickFix scam now reads exactly like a real Google or Cloudflare interface.
  • It is being sold as a service. Ready-made kits and loaders package the entire ClickFix scam flow, letting low-skill criminals launch professional campaigns for a subscription fee. Security researchers documented these kits expanding with new payloads throughout mid-2026.
  • Google put it on the map. When Google's June 2026 frauds and scams advisory named ClickFix fake-update lures as one of three techniques directly targeting Gmail users, it confirmed what threat teams were already seeing: the volume had crossed from niche to widespread.

The result is that the standard advice — "don't open strange attachments, watch for typos" — no longer catches the threat. The ClickFix scam contains no attachment and no typos. It relies entirely on getting you to perform one trusting action, and it has been engineered to make that action feel completely routine. For a fuller picture of the 2026 threat landscape, our breakdown of Google's June 2026 scam advisory covers all three named techniques side by side.

How a ClickFix Attack Unfolds, Step by Step

Every ClickFix scam follows the same basic script, whether the lure arrives by email, ad, or compromised website. Understanding the sequence is the surest way to interrupt it before the final step.

  1. The lure. You receive an email, message, or link that leads to a web page. In the Gmail context this is usually a phishing email dressed as a shared document, a delivery notice, a subscription alert, or a security warning.
  2. The fake problem. The page displays an obstacle — a CAPTCHA that "failed," a document that "won't load," or a browser that "needs an update." It creates mild urgency and a sense that you are one step away from your goal.
  3. The instructions. The overlay gives you keyboard steps: on Windows, "Press Windows + R," then "Press Ctrl + V," then "Press Enter." On a Mac, it may point you to Terminal instead. These steps look like harmless verification.
  4. The silent clipboard. Here is the trick you never see. The moment you interact with the page, it copies a hidden command to your clipboard using JavaScript. When you paste, you are not pasting anything you chose — you are pasting the attacker's command.
  5. The execution. Windows + R opens the Run dialog. Pasting drops in the command. Enter runs it. The command typically launches PowerShell in a hidden window, reaches out to an attacker-controlled server, and downloads and runs the real payload — an infostealer, a remote-access tool, or a loader for further malware.
  6. The payoff. Within seconds the malware harvests saved passwords, browser cookies, and session tokens. Those stolen session cookies are the crown jewels: they can let an attacker into your Gmail without ever needing your password or two-factor code.

That last point connects ClickFix to a broader 2026 problem. Stolen session cookies power account takeover that skips two-factor authentication entirely — the same mechanism we cover in our guide to Gmail session hijacking and cookie theft. ClickFix is simply one of the most effective ways to plant the infostealer that grabs those cookies in the first place.

The Gmail Connection: How the Lure Reaches Your Inbox

ClickFix is a delivery technique, not a Gmail-specific bug — but Gmail is one of its primary distribution channels for a simple reason: it is where two billion people receive links they are inclined to trust. A ClickFix scam that reaches you through your inbox borrows the credibility of everyone who has ever legitimately emailed you.

The most common Gmail-borne lures in 2026 look like this:

  • Shared-document notifications. A message mimics a "Someone shared a document with you" alert. The link leads to a fake preview page that claims you must "verify you are human" before the file will open.
  • Delivery and invoice notices. A parcel is "held" or an invoice "needs review." Clicking through lands on a page that says your browser must be updated to display the document.
  • Meeting and calendar bait. A fake meeting link or calendar invite pushes you to a "join" page gated behind a bogus verification step. Attackers often pair this with QR codes to move you onto a phone, where security tooling is thinner.
  • Fake security alerts. Ironically, some ClickFix lures pose as security warnings — "unusual sign-in detected, verify your device" — turning your caution against you.

Because the malicious action happens on an external web page rather than inside the email, these messages frequently slip past filters that would catch a malware attachment. The email itself may contain nothing but a plausible sentence and a link. That is why inbox hygiene alone cannot stop a ClickFix scam; recognizing the fake verification page is the decisive skill. Layering on the habits in our Gmail account security tips reduces how many of these lures ever reach you, but the last line of defense is always your own hesitation at the paste step.

What the Pasted Command Actually Does

To respect the danger, it helps to understand what you would be running. A typical ClickFix scam command is a single line that invokes PowerShell (on Windows) with flags that hide the window and skip normal profile loading, then fetches a script from a remote server and executes it immediately in memory. Because the payload is pulled from the internet at runtime and often runs without ever being written to disk, traditional file-scanning antivirus may never get a sample to inspect.

The downloaded payload is usually an infostealer. Within moments it can:

  • Extract saved usernames and passwords from your browser's password store.
  • Copy authentication cookies and active session tokens for Gmail, banking, and social accounts.
  • Harvest autofill data, crypto wallet files, and cloud-service credentials.
  • Install a persistence mechanism so the attacker keeps access after a reboot.

The stolen session cookies deserve special emphasis. A session cookie is what keeps you logged in after you authenticate. If an attacker steals a live Gmail session cookie, they can import it into their own browser and be logged in as you — no password prompt, no two-factor challenge, because from Google's perspective you already passed both. This is precisely why enabling two-factor authentication, while essential, is not a complete defense against a ClickFix scam. The malware steals the result of your login, not the login itself. Moving to phishing-resistant sign-in like Gmail passkeys and enrolling high-value accounts in Advanced Protection are the upgrades that meaningfully raise the bar.

ClickFix vs Other 2026 Gmail Threats

ClickFix rarely travels alone. It sits alongside the other techniques Google flagged in 2026, and each attacks a different layer of your trust. Knowing how they differ helps you recognize which one you are facing.

Threat The hook What it steals Core defense
ClickFix scam Fake CAPTCHA or update asks you to paste a command Installs infostealer; grabs passwords and session cookies Never run a pasted command to "verify" yourself
Adversary-in-the-Middle Look-alike login page proxies the real one Session cookie captured during a genuine login Passkeys; check the exact URL
Calendar invite phishing Fake event auto-added to your schedule Sends you to a phishing form via a reminder Disable auto-add of invitations
Prompt-injection alerts Hidden text tricks an AI summary into a fake warning Pushes you to call a fake support number Ignore instructions inside summarized email

The common thread is that all four are engineered to feel like routine, trustworthy actions rather than obvious spam. The ClickFix scam is distinctive because it turns you into the delivery mechanism, which is why it slips past tools that would stop a download cold.

Red Flags: How to Spot a ClickFix Page

Once you know the pattern, a ClickFix scam becomes easy to catch. Train yourself and your team to stop the instant any of these appear:

  • Any instruction to press Windows + R, Ctrl + V, and Enter. This is the single loudest signal. No legitimate verification, CAPTCHA, or software update has ever required you to open the Run dialog and paste something.
  • A "verification" step that sends you outside the browser. Real CAPTCHAs are solved inside the web page. If a check tells you to open Terminal, PowerShell, or system settings, it is an attack.
  • Instructions to paste when you never copied anything. If a page tells you to paste and you did not deliberately copy text, the page put something on your clipboard. Do not paste it anywhere.
  • "Update your browser to view this content." Browsers update themselves; websites never deliver updates. Any page pushing a manual update or codec install is a lure.
  • Urgency layered on a trivial task. "Complete this step within 60 seconds" attached to a simple CAPTCHA is manufactured pressure meant to short-circuit your judgment.

The mental rule to memorize is short: proving you are human never requires running a command. If any page — arriving from Gmail or anywhere else — asks you to paste and run something to continue, close the tab. There is no legitimate scenario where that request is real.

How to Protect Yourself and Your Team

Defending against the ClickFix scam is a mix of one behavioral rule and several technical safety nets. The behavior does most of the work; the technical layers limit the damage if someone slips.

The one rule that stops it: never paste and run a command that a web page or email told you to. Not to verify yourself, not to update, not to fix an error. This single habit defeats every ClickFix scam regardless of how convincing the page looks.

Technical safeguards worth putting in place:

  • Adopt passkeys for Gmail. Passkeys are cryptographically bound to the real Google domain and cannot be replayed from a stolen cookie the way passwords can. Our passwordless passkey guide walks through setup.
  • Enroll critical accounts in Advanced Protection. Google's Advanced Protection Program blocks much of the cookie-theft leverage that infostealers rely on and hardens the recovery process.
  • Run Google's Security Checkup regularly. It surfaces unfamiliar devices, active sessions, and third-party access — the footprints an infostealer leaves behind.
  • Keep the operating system and browser current. Automatic updates close the vulnerabilities that some payloads chain into, and reduce the window a persistence mechanism can exploit.
  • Use a reputable endpoint protection tool. While ClickFix dodges download scanning, good behavioral protection can flag a hidden PowerShell process reaching out to an unknown server.
  • Segment accounts by risk. Do not let one compromised machine expose every account you own. Separate browsers or profiles for high-value logins contain the blast radius.

For teams, the highest-leverage move is training. Show staff a real ClickFix scam page, walk them through the "press Windows + R" instruction, and make the rule unmissable: no pasted commands, ever. A five-minute demonstration prevents an incident that could cost weeks. Pair that with the fundamentals in our Gmail security checklist for a durable baseline.

What to Do If You Already Pasted the Command

If you followed a ClickFix scam's instructions and ran the command, treat it as a genuine compromise and move quickly. Speed matters because infostealers work in seconds.

  1. Disconnect the device from the internet. Pull the Wi-Fi or unplug the cable to cut the malware's connection to its server and slow any ongoing data theft.
  2. From a different, trusted device, change your Google password. Do not use the possibly infected machine. Changing the password from a clean device begins invalidating stolen credentials.
  3. Sign out of all sessions. In your Google Account security settings, revoke access on all devices. This kills the stolen session cookies that let an attacker skip your password and two-factor prompt.
  4. Run Google's Security Checkup. Review devices, recent security events, and third-party app access. Remove anything you do not recognize.
  5. Check for hidden forwarding rules and filters. Attackers frequently add rules to quietly forward or delete mail. Inspect Gmail's Forwarding and Filters settings carefully.
  6. Rotate other exposed passwords. Any password saved in the browser on that machine should be considered stolen. Prioritize email, banking, and anything reused.
  7. Fully clean or reimage the device. Because the payload may include persistence, a thorough malware scan — or ideally a full operating-system reinstall — is the only way to be confident the machine is clean.

If you find yourself locked out during the incident, our Gmail account recovery guide covers the emergency steps to reclaim access, and the process is markedly smoother on an established account with strong recovery options already in place.

ClickFix and Multi-Account Operations

If you run outreach, agency work, or any operation that spans many inboxes, the ClickFix scam carries an amplified risk. One infected workstation can leak the session cookies for every account logged in through that browser at once. A single careless paste can hand an attacker a whole fleet.

That reality argues for a few operational disciplines. Isolate accounts so that no single device or browser profile holds sessions for all of them — compartmentalization means one compromise cannot cascade. Standardize the "no pasted commands" rule across everyone who touches the accounts, including contractors and virtual assistants, since they are often the ones clicking through unfamiliar verification pages under time pressure. And build on accounts with genuine history and strong recovery options, because when an incident does happen, recovery speed determines how much you lose.

This is one more reason established accounts outperform disposable ones for serious work. It is not that an aged account resists the initial infostealer any better — the malware treats every session cookie the same. The advantage is resilience: aged accounts carry well-established recovery emails, phone numbers, and a long, consistent sign-in history that Google weighs when verifying the real owner during a dispute. If you are sourcing established Gmail accounts for business, pair that structural trust with the hardening above, and a ClickFix incident becomes a contained scare rather than a catastrophe.

Frequently Asked Questions

What is the ClickFix scam in simple terms?

The ClickFix scam is a trick that disguises malware installation as a verification or repair step. A web page shows a fake CAPTCHA or "update needed" message and tells you to press a keyboard shortcut, paste a command, and press Enter. The page has secretly copied a malicious command to your clipboard, so when you paste and run it, you install malware yourself — bypassing the download warnings that browsers and antivirus rely on.

How does the ClickFix scam reach Gmail users?

It arrives as a phishing email disguised as a shared document, delivery notice, invoice, calendar invite, or security alert. The email itself is often just a plausible line of text and a link, so it slips past filters that would catch a malware attachment. The malicious action happens on the external web page the link opens, where you are shown the fake verification step. Recognizing that fake page is the key defense, since the email may look harmless.

Can antivirus stop a ClickFix attack?

Not reliably. Because you run the command manually and the payload is often pulled from the internet and executed in memory without being saved to disk, traditional file-scanning antivirus may never get a file to inspect. Good behavioral endpoint protection can sometimes flag the hidden PowerShell process reaching out to an unknown server, but the dependable defense is behavioral: never paste and run a command a page told you to.

Does two-factor authentication protect me from ClickFix?

Only partially. Two-factor authentication protects your login, but the infostealer a ClickFix scam installs steals your active session cookies — the tokens that keep you logged in after you already passed two-factor. With a stolen cookie, an attacker can enter your account without a password or code. Passkeys and Google's Advanced Protection Program address this gap far better than SMS or app-based codes alone.

I pasted the command. What should I do first?

Disconnect the device from the internet immediately, then use a different, trusted device to change your Google password and sign out of all sessions to kill any stolen cookies. Run Google's Security Checkup, remove unknown devices and app access, and inspect Gmail for hidden forwarding rules or filters. Finally, treat the affected machine as infected and reimage it, since the malware may have installed persistence.

Is ClickFix only a Windows problem?

No. While most campaigns target Windows using the Run dialog and PowerShell, the same social-engineering pattern has been adapted for macOS by directing victims to the Terminal app, and for other platforms as well. The underlying rule is universal across every operating system: legitimate verification never requires you to open a command tool and run something, so any page asking you to do that is an attack.

The ClickFix scam is clever, but it has one fatal weakness: it needs your cooperation. Every version of it depends on you performing a single trusting action — pasting and running a command. Refuse that one step and the entire attack collapses, no matter how polished the page looks. Slow down at any "verify you are human" prompt, never run a pasted command, move your accounts to passkeys, and you defeat it. For more on keeping your Gmail accounts secure and trusted at scale, message us on Telegram @mixgmail or explore our aged Gmail accounts built for reliable, long-term use.

Aged Gmail Account

Buy old Gmail accounts starting at just $1. Aged from 6 months to 15 years. Instant delivery via Telegram.


From $1 per account
In Stock ⚡ Instant Delivery
Order on Telegram Chat on WhatsApp