26/05/2026
If a website tells you to press Windows Key + R – close the tab immediately.
This is a growing scam called ClickFix, used to install infostealer malware that steals passwords, session data, and stored payment details.
It usually starts with a fake CAPTCHA asking you to press Win + R, paste a command, and hit Enter. The moment you do, you’ve installed malware yourself — no download, no warning, nothing for antivirus to detect.
Because you run the command manually, it bypasses most security tools completely.
How to protect your team:
- Never follow instructions telling you to use Win + R from a website
- Restrict PowerShell access for non-IT users
- Ensure endpoint protection uses behavioural detection, not just signatures
These scams are designed to look convincing. But once your team knows the signs, they can stop them instantly.