Loading…
Skip to content
All journal
Cyber SecurityPhishingCloudflare

Fake Cloudflare checks: how to spot a ClickFix scam

A familiar verification screen can hide a request to run malware yourself. Learn how to recognise fake Cloudflare checks and respond without making things worse.

Rootscratch ·

Illustration of a laptop showing a fake browser verification prompt used in a ClickFix scam.

AI-generated illustration of a fake verification prompt, not a screenshot of a live attack.

A page says it needs to verify that you are human. It looks familiar, perhaps with Cloudflare branding. Then it asks you to open a system tool and paste a command.

Stop there. Legitimate Cloudflare browser challenges do not require you to run pasted operating-system commands. That request is a warning sign of ClickFix, a social-engineering technique that persuades people to run malicious instructions themselves.

Attackers imitate a trusted security check to make the request feel routine. The copied branding is not evidence that Cloudflare has been compromised, and an ordinary CAPTCHA or verification screen is not, by itself, evidence of a scam.

How the fake verification works

ClickFix gives you an apparent problem, such as a failed browser check, and supplies a supposed fix. A button may copy a command to your clipboard while the page tells you how to run it outside the browser.

In its 21 August 2025 analysis, Microsoft documented pages impersonating Cloudflare Turnstile, including a fake verification checkbox followed by instructions to run a copied command. It also observed lures reached through phishing, malicious advertisements and compromised websites.

That last detail matters: recognising a website does not make every prompt on it trustworthy.

The consequences depend on the campaign. Microsoft documented information-stealing malware and remote-access tools among the payloads delivered through ClickFix. Its research covers Windows and macOS, so Mac users should not dismiss this as a Windows-only problem.

ClickFix is a technique, not one specific piece of malware. Proofpoint's research published on 17 April 2025 documented variations used by several threat groups. You do not need to identify the group or malware to recognise an unsafe request.

What should a real Cloudflare check ask you to do?

Cloudflare's Challenges documentation, updated 15 April 2026, describes checks performed by the browser and minimal interaction, such as checking a box or selecting a button. Most visitors pass automatically.

A request to open PowerShell, Terminal, Command Prompt or the Windows Run dialog and execute pasted text is outside that visitor-verification process. This distinction concerns browser challenges; developers may legitimately use command-line tools when administering their own services.

Watch for these signs:

  • A verification screen asks you to leave the browser and open a system tool.
  • It says a command has been copied for you and must be run to continue.
  • A supposed browser repair requires software installation or turning off security protection.
  • The instructions pressure you to finish quickly or repeat the process after an error.

A familiar logo and polished wording do not establish who created a page. Check the address, but remember that compromised legitimate sites can also carry a lure. The requested action is the most useful warning here.

What to do depends on how far you got

You only saw the page

Close it without following its instructions. Reach the service through a trusted bookmark or a separately checked address. If it is a work-related service, report the suspicious page through your usual IT channel.

Seeing a ClickFix lure does not, on its own, establish that your device is infected. These attacks rely on getting you to perform an additional action. Do not follow any “cleanup” advice supplied by the same page.

You clicked or copied, but did not run anything

Do not paste the clipboard contents into a terminal or Run dialog to inspect them. Close the page and replace the clipboard contents by copying harmless text from a trusted document.

Copying text alone is different from executing it. If you pasted it into a system tool, cannot tell whether it ran, or also opened a downloaded file, report that uncertainty rather than assuming nothing happened.

You ran the command

Stop using the device for logins or sensitive work. Contact your IT or security team immediately using another device, and follow its incident-response instructions. Explain what happened and approximately when.

Isolate the affected device from networks promptly. For a personal computer without managed IT support, disconnect Wi-Fi and unplug Ethernet, then seek qualified help. CISA's September 2023 response guidance recommends isolating impacted systems; isolation limits communication but does not remove malware.

Use a separate, known-clean device for account recovery. Prioritise email and other sensitive accounts, change affected passwords and revoke active sessions where the service supports it. For work accounts, coordinate these steps with IT. Record the page address if already available, but do not reopen the lure or rerun the command to collect evidence.

An assessment may call for security scans or rebuilding the device. A scan with no findings is not a guarantee that no information was stolen.

For businesses and developers

Give staff a clear reporting route and permission to stop when a verification step feels wrong. Include this scenario in awareness training without blaming people who report a mistake.

IT teams should review endpoint protection, application controls and access to scripting tools according to actual job needs. Microsoft recommends layered protection and device hardening; blanket restrictions may disrupt legitimate development work.

If visitors report this behaviour on your own site, have your web and security teams investigate page scripts and recent changes. Do not assume disabling Cloudflare will solve it. Share the practical rule with your team: a browser verification request should never be your reason to run an unfamiliar system command.

From Koronadal City

Tell us what you need to build or improve.

Based in Koronadal City, South Cotabato, Mindanao. Working remotely with businesses throughout the Philippines and worldwide.