How ClickFix Attacks Work—and How CrowdStrike Says It Disrupts Them

Summary
ClickFix tricks users into running commands from deceptive webpages. CrowdStrike describes activity attributed to STARDUST CHOLLIMA and VOODOO BEAR, and outlines browser, endpoint, identity, and monitoring defenses.
Key points
- ClickFix uses fake meeting errors, CAPTCHAs, or other prompts to persuade users to paste commands into trusted tools such as Windows Run or PowerShell.
- The commands can launch scripts that download malware, steal credentials, establish persistence, or enable further access.
- CrowdStrike says STARDUST CHOLLIMA likely used a fake video-conferencing site in July 2026 to deliver a PowerShell- and VBScript-based infection involving GeniexLoader and GeniexRAT.
- CrowdStrike attributes fake-CAPTCHA intrusions affecting organizations in France, the United States, and Canada to likely VOODOO BEAR activity using compromised Ukrainian websites.
- CrowdStrike's 2026 Global Threat Report documented a 563% increase in incidents involving fake CAPTCHA lures in 2025.
- The article recommends layered defenses across browsers, endpoints, identity, and security monitoring to disrupt execution, credential abuse, and follow-on activity.