Reference
Lure themes
A lure theme is the story a ClickFix page tells about why you should paste a command. It is not the payload and not the kit — those change constantly. The story changes slowly, because it has to keep working on people, and people change slowly. That makes the pretext the most durable thing to learn.
Each theme below is described in prose. There are no screenshots and no reproduced page markup anywhere on this site, deliberately: a faithful copy of a fake verification page is a fake verification page. Start with the explainer if the technique is new to you.
All lure themes
Fake CAPTCHA verification
Windows · macOSThe dominant ClickFix pretext. A page imitates a human-verification challenge, then replaces the puzzle with keyboard instructions presented as the way to complete the check. It works because verification is one of the few things on the web where being told to perform an odd little ritual is normal, so the instruction does not stand out.
First reported 2024-09Read →Fake browser update
Windows · macOSThe oldest ClickFix pretext, and still in service. An overlay claims the browser is out of date and must be updated before the page will load. Where an earlier generation of fake-update pages offered a file to download, the ClickFix version asks for a command to be run instead — which is what lets it walk past the download reputation checks that had made the file version expensive.
First reported 2024-03Read →Cloudflare Turnstile clone
Windows · macOSA close imitation of Cloudflare's browser-check interstitial — the page millions of people see and dismiss without reading. It borrows the layout, the wording and usually a fabricated reference identifier so that whatever follows reads as part of a routine security check. Technically it is a fake-CAPTCHA lure; it earns its own entry because the costume is specific, extremely familiar, and unusually well made.
First reported 2024-10Read →Fake meeting or conferencing app
Windows · macOSA page imitating Zoom, Google Meet or Microsoft Teams that reports the call cannot start, usually blaming the microphone or camera. The remedy on offer is a pasted command. This theme is normally reached through an invitation rather than through browsing, which makes it the most targeted of the set — and it is the one most often aimed at macOS.
First reported 2024-08Read →Corrupted document or repair prompt
WindowsA shared-document link that lands on a viewer page claiming the file is damaged, encoded incorrectly, or missing a component, with a manual repair offered as the fix. This is the workplace variant: it arrives with a sender, a subject line and a reason to exist, so it is judged against the dozen legitimate document links the recipient opened that week rather than against the open web.
First reported 2024-11Read →Generic browser or system error
Windows · macOSThe residual category, and a large one. Any page that states a vague technical failure and supplies a copy-and-paste remedy belongs here: a missing extension, an unavailable font, a rendering fault, an invented Windows error code. The pretext is deliberately thin, because the instruction is doing all the work and a more specific story would only give the reader something to check.
First reported 2024-05Read →Download gate verification
Windows · macOSA verification step wedged between a visitor and a file they were already trying to get: cracked software, a game modification, a media file, a driver. The audience arrives motivated and slightly furtive, which is a poor state in which to question an odd instruction. Unlike most themes, this one is usually reached through SEO poisoning and paid ads rather than through a compromised legitimate site.
First reported 2024-10Read →
The tell-tale signs, in one place
If you are looking at a page right now and want an answer quickly, this is the list. Every one of these reduces to the same rule, which is worth learning on its own: no legitimate website will ever ask you to press Windows+R, to open Terminal, or to paste anything into either one.
- Fake CAPTCHA verification
- A real CAPTCHA is solved inside the browser window. If verification asks you to press keys outside the browser — the Run dialog, Terminal, anything that takes a command — it is not verification.
- Fake browser update
- Browsers update themselves, from inside the browser. Chrome, Edge, Firefox and Safari have never shipped an update through a web page, and no browser update has ever needed you to run a command.
- Cloudflare Turnstile clone
- A genuine Cloudflare check is passive. It resolves on its own and asks you for nothing at all — least of all the Run dialog or Terminal.
- Fake meeting or conferencing app
- Conferencing platforms diagnose devices inside their own application, and their fixes are buttons. Check the address bar as well: a real Meet, Zoom or Teams link lives on the platform's own domain.
- Corrupted document or repair prompt
- Repairing a document is something a document application does. Word, Excel, Adobe Reader and every cloud viewer repair files from inside themselves. None of them has ever needed the operating system's Run dialog to open a file.
- Generic browser or system error
- Real errors from a browser or an operating system do not arrive with instructions to open a command prompt. A page that hands you the remedy along with the problem is describing a problem it invented.
- Download gate verification
- No file host needs the Run dialog or Terminal to release a download. If a download requires a command, the command is the download.