Ars Technica · July 17, 2026 · 1Cifer
Even elite hackers have switched to ClickFix: victims are asked to hack themselves
Ars Technica reports that even the most capable state hacking groups have switched to the ClickFix technique. The scheme is disarmingly simple — the user is shown a plausible "error" window with step-by-step instructions to "fix" it: copy this command, paste it, press Enter. By following along, the person launches malicious code with their own hands.
The technique's popularity among elite groups comes down to effectiveness: antivirus and filters are helpless when the action is performed by the legitimate user. And generative AI has made the lures flawless — the windows, emails and "support instructions" no longer betray themselves with clumsy language or design.
For a company in Kazakhstan the defense lies in habits, not software. Introduce one simple rule and repeat it to the point of reflex: never execute commands or paste text into a terminal or address bar at the direction of a pop-up, an email or a website — any "fix instruction" goes to IT first. A five-minute ClickFix debrief at your next staff meeting will protect the company better than another security product.


