Monocera · ISO 27001 · C.A.R.L.
Client Advisory · Cyber Security
24 September 2026
Incident debrief: social engineering

ClickFix: An evolving threat.

We met a new client this week to run through our cybersecurity framework, C.A.R.L., and what implementing it would look like for their business. Their existing environment was semi-self-managed by some technical staff, and MDR was already in place. A far cry ahead of most SMEs we encounter.

The meeting concluded with clear next steps to agree on timings for implementation.

Fast forward four hours.

We saw a notification come through from their vendor-managed SOC. The client's endpoint protection had caught a malicious PowerShell command the moment it ran. It blocked execution, cleaned up, and the managed detection team passed the case as Medium severity. Process tree, scheduled tasks, registry, persistence mechanisms. All reviewed, all clean. No malware had been installed.

On the face of it, a fairly textbook response. But before we could even pick up the phone, more than A$100,000 had left the client's bank account.

What actually happened

It started the way these increasingly do. A staff member, doing nothing particularly out of the ordinary, landed on a page that told them to prove they were human.

Press the Windows key and R. Paste this text. Press Enter.

They did. That is ClickFix.

The verification step was actually a command that reached out to a random-string web address and piped whatever came back straight into PowerShell. The logs told the story: File Explorer launching PowerShell directly, consistent with a person being walked through the Run box by hand. The security tooling caught this, stopped it, and cleaned it up.

If the story ended there, it would have been a good day. It didn't.

The move endpoint protection doesn't always stop

Seconds after the blocked command, something else launched from the user's Downloads folder: a legitimate remote-access tool. The same kind of software IT teams use every day. And that's important. Remote-access software has perfectly legitimate business uses, which can make its malicious use much harder to distinguish without the right controls and context.

The attacker, unable to get their own code to run, had instead talked the user into handing over the keyboard. Once a human is sitting on the machine in real time, they don't necessarily need malware, scheduled tasks or registry tricks.

That's why “no persistence found, Medium severity” can be technically accurate while still not telling the whole story. The endgame wasn't the device itself. It was the money: access to an already signed-in banking session and fraudulent transfers that endpoint security alone was never designed to prevent.

This is not a rare edge case

47%
of initial-access cases investigated by Microsoft Defender Experts, per Microsoft's 2025 Digital Defense Report
517%
increase in ClickFix activity reported by ESET over a six-month period
20%+
of already-warned recipients still engaged with trusted-platform lures in 2026 simulations

The technique has expanded beyond Windows to target macOS, and MITRE ATT&CK now tracks malicious copy-and-paste techniques such as ClickFix.

The point isn't that security awareness doesn't work. It does. The point is that awareness can't be the only control.

Four takeaways from this incident

01
Don't run code because a webpage tells you to
No legitimate CAPTCHA should require you to paste a command into Run or Terminal. If a webpage suddenly starts giving you keyboard instructions, stop and verify with your IT team.
02
Control which remote-access tools can run
AnyDesk, TeamViewer and similar tools have legitimate uses, but organisations should know which are sanctioned. An unexpected remote-access client in a Downloads folder warrants attention.
03
Treat "malware blocked" as the start of the investigation
Blocking the initial activity doesn't always mean the attack is over. What happened immediately before and after the detection can be just as important as what was blocked.
04
Don't assume the endpoint is the final target
If an attacker has interactive access to a user's machine, consider what else that exposes: credentials, active sessions, email, financial systems, and other business applications.

The bigger lesson

This user wasn't reckless, and the technology wasn't necessarily broken. A person was manipulated into trusting the wrong prompt. The initial malicious activity was detected and blocked. The attacker then found another path.

Cybersecurity isn't about expecting one product to stop every possible attack. It's about understanding how your people, processes and technology work together, and what happens when one layer is bypassed.

That's the thinking behind C.A.R.L., our Cybersecurity and Resilience Lifecycle®. It helps us look beyond individual security products and assess how the broader environment holds up when something doesn't go according to plan. The most useful time to find those gaps is before an attacker does.

Monocera® · Augmenting Business®September 2026