ClickFix Social Engineering: The New “Win+R” Threat to Malaysian SMEs

Hand pressing Win key on keyboard with floating PowerShell Run dialog box and red digital background.

TL;DR / Critical Alert

  • What is it? A fake error message that tricks you into copy-pasting a “fix” script into your system.
  • The Trap: Because you run the script, your antivirus often thinks it’s safe.
  • The Result: Steals your browser passwords, crypto wallets, and company emails in seconds.
  • Protection: Never, ever copy-paste a command from a website into your Windows “Run” dialog or PowerShell.

Introduction: The Scam That Bypasses Your Firewall

Imagine you’re on a website, and a professional-looking box pops up: “Google Chrome failed to update. Click here to fix.” You click, and it tells you to press Win+R, paste a specific code, and press Enter.

You think you’ve just fixed your browser.

In reality, you’ve just manually invited a hacker into your company’s network. This is the ClickFix attack, the fastest-growing social engineering threat in Malaysia between 2024 and 2026.

According to cybersecurity firm Proofpoint, ClickFix attacks increased by over 500% globally between 2023 and 2025. In Malaysia, where many SMEs lack dedicated IT security teams, the attack has become particularly effective. The Royal Malaysia Police (PDRM) Commercial Crime Investigation Department reported that social engineering attacks—including ClickFix—accounted for 31% of all cybercrime losses in 2025.

Unlike traditional viruses that try to “break in,” ClickFix tricks you into opening the door. This guide explains why this attack is devastating for Malaysian SMEs and how you can train your staff to spot it.

1. How the ClickFix Attack Works (The “Fix” Illusion)

The brilliance of ClickFix is its simplicity. It exploits human helpfulness and technical anxiety.

The 4-Step Trap:

  1. The Fake Error: While browsing a compromised site, an overlay appears that mimics a system error (e.g., “CAPTCHA Verification Failed” or “Browser Update Required”).
  2. The Instructions: The prompt tells you that to fix the error, you need to execute a command. It even provides a “Copy” button for the script.
  3. The Execution: You are instructed to open the Windows Run dialog (Win+R) or PowerShell, paste the script, and hit Enter.
  4. The Infection: The script is a “fileless” piece of malware. It connects to the hacker’s server and downloads an “Infostealer” (like Lumma Stealer) that immediately scans your computer for every saved password and credit card.

Why it’s dangerous: Most antivirus software is designed to stop unauthorized scripts. Because you are the one pressing “Enter,” the system thinks the command is authorized by the user.

What is an Infostealer?

An infostealer is a type of malware designed to silently collect sensitive information from an infected device. It targets browser-saved passwords, session cookies, cryptocurrency wallet files, email credentials, and autofill data. Popular infostealers used in ClickFix attacks include Lumma Stealer, RedLine, and Raccoon Stealer. The stolen data is then sold on dark web marketplaces or used directly for further attacks.

2. Why Malaysian SMEs are Primary Targets

In 2024, Malaysia recorded over 19.6 million cyberattacks. By early 2026, ClickFix has become a favorite for hackers targeting local businesses for several reasons:

  • The “FOMO” and Urgency Culture: Malaysian employees are highly responsive to urgent “system alerts,” especially during busy work hours.
  • Mobile-to-Desktop Transition: Many workers scan QR codes that lead to these compromised “update” pages on their office PCs.
  • Localized Lures: Hackers are now using AI to write these “Fix” prompts in perfect English and Bahasa Malaysia, making them seem official.
  • Lack of IT Staff: Many Malaysian SMEs with fewer than 20 employees have no dedicated IT security personnel, meaning there’s no one to verify suspicious “fix” instructions.

3. The Impact: What Happens After You Press “Enter”?

Once the ClickFix script runs on an office computer, the damage is near-instant:

  • Credential Theft: Every password saved in Chrome, Edge, or Firefox is stolen.
  • Session Hijacking: Hackers steal your “session cookies,” allowing them to log into your company’s email or Facebook Business Manager without needing MFA.
  • Internal Spreading: The hacker uses the infected computer to scan your office network and find your server or NAS to launch a [Ransomware attack].

The Session Cookie Problem

Most people think MFA (Multi-Factor Authentication) protects them. But ClickFix steals session cookies—the temporary tokens that keep you logged in. With these cookies, the hacker can access your accounts as if they were you, bypassing MFA entirely. This is why SMS-based MFA is no longer sufficient; FIDO2 hardware keys or app-based MFA are the only reliable defenses.

4. Real-World Scenario: The $1.5 Billion Lazarus Crypto Heist (2025)

The most devastating real-world use of this exact trick was executed by the North Korean state-sponsored hacking group, Lazarus.

  • The Attack: They targeted software developers in the cryptocurrency space with fake job interviews. When the victims went to do the video interview, a popup claimed their camera/microphone was blocked and they needed to install a “driver.”
  • The Trick: The popup instructed the victims to press Win+R and paste a command.
  • The Result: The command installed an infostealer that bypassed their antivirus. Lazarus ultimately used this access to steal $1.5 billion in cryptocurrency from the platform Bybit.

Read More: ClickFix: How Hackers Use ‘Verification’ to Steal Your Information

5. How to Protect Your Office from ClickFix

The defense against ClickFix is 90% human and 10% technical.

Staff Training (The Golden Rule):

Never copy-paste commands from a website into your system. Legitimate updates for Chrome, Windows, or Zoom will never ask you to open a terminal or the Run dialog manually.

Technical Defenses:

  1. Implement EDR: Standard antivirus is not enough. You need Endpoint Detection and Response (EDR) that monitors behavior and blocks “PowerShell” from making suspicious external connections. (See our Antivirus vs. EDR Guide).
  2. Restrict PowerShell Access: Unless your employees are IT admins, they don’t need access to PowerShell or the Run dialog. Your IT manager can restrict these via Group Policy.
  3. Use MFA (The Right Way): Since hackers can steal session cookies, use FIDO2 Hardware Keys or App-based MFA instead of SMS, which is easier to bypass.
  4. Browser Isolation: Consider using browser isolation tools that run web sessions in a sandboxed environment, preventing scripts from accessing local system resources.

ClickFix Defense Checklist for SMEs

Defense LayerActionCostPriority
Staff TrainingTeach “never paste commands from websites”Free🔴 Critical
EDRDeploy behavioral endpoint protectionRM200–RM600/endpoint/year🔴 Critical
Restrict PowerShellDisable via Group Policy for non-IT staffFree🟡 High
FIDO2 MFAReplace SMS MFA with hardware keysRM100–RM200/key🟡 High
Browser IsolationRun web sessions in sandboxRM50–RM150/user/month🟢 Medium

Conclusion: The Human Firewall is Your Best Asset

The ClickFix attack is a reminder that hackers have stopped hacking systems; they are now “hacking” people. By training your team to be skeptical of “urgent fix” pop-ups, you build a human firewall that is stronger than any software.

The single most important rule to teach your staff: No legitimate software will ever ask you to copy-paste a command into the Windows Run dialog or PowerShell. If you see this instruction, it is always a scam.

FAQ: ClickFix Attacks in Malaysia

Q1: I think I ran a ClickFix script. What should I do?
A: Immediately disconnect the computer from the internet (unplug the LAN or turn off WiFi). Use a different device to change every single password you had saved on that computer. Contact an MSP for a full system scan.

Q2: Can ClickFix happen on a Mac?
A: Yes. While the current wave targets Windows “Win+R,” similar attacks use the “Terminal” on MacOS to achieve the same result.

Q3: Is ClickFix related to phishing?
A: Yes, it is a form of “In-Browser Phishing.” Instead of stealing your password on a fake site, it steals your entire session via a script.

Q4: Will my insurance cover a ClickFix attack?
A: Most Cyber Insurance policies cover “social engineering” if you can prove you had basic security training in place. (Check your policy for “Funds Transfer Fraud” or “Cyber Extortion”).

Q5: What is Lumma Stealer?
A: Lumma Stealer is one of the most popular infostealers used in ClickFix attacks. It is sold as “Malware-as-a-Service” on dark web forums for as little as USD250/month. It targets Chromium-based browsers (Chrome, Edge, Brave) and can exfiltrate passwords, cookies, and crypto wallets within seconds of execution.