ClickFix attacks have taken a troubling new turn. Cybercriminals are now building convincing fake ChatGPT interfaces — custom-branded AI tools that look and feel legitimate — to trick employees into running malicious commands on their own machines. For small and medium businesses, this is exactly the kind of threat that slips past traditional defences, because it relies on human behaviour rather than technical vulnerabilities.
What Is a ClickFix Attack and Why Should You Care
A ClickFix attack is a social engineering technique where a victim is shown a fake error message or prompt, then instructed to "fix" the problem by copying and pasting a command into their computer. It sounds almost too simple to work. But it does, repeatedly, because the instructions appear to come from a trustworthy source — and right now, few sources feel more trustworthy to everyday users than an AI assistant.
In the latest wave of these attacks, threat actors are deploying custom-built ChatGPT lookalikes. These fake tools are promoted through ads, phishing emails, and even legitimate-looking websites. When an employee interacts with the fake AI, they are eventually presented with an error or a verification step that asks them to run a script. That script installs a Remote Access Trojan, or RAT — malware that gives the attacker full, silent control over the infected machine.
Once a RAT is installed, the attacker can watch keystrokes, steal saved passwords, access files, and move laterally through your business network. Credentials harvested this way routinely end up for sale on dark web markets within days.
Why SMBs Are the Primary Target
Large enterprises typically have security awareness programmes, endpoint detection tools, and dedicated IT staff who can spot anomalies quickly. Small and medium businesses often do not. Attackers know this. A convincing fake AI tool requires almost no technical knowledge to fall for, and employees who use AI tools regularly as part of their workflow are especially vulnerable — they are used to following prompts from these interfaces.
The credibility of AI branding is a serious amplifier here. Workers who would hesitate before clicking a suspicious link may not think twice about following a step-by-step instruction from something that looks like an official ChatGPT tool. The psychological trust built around AI assistants is being weaponised directly against your team.
For businesses that have not locked down which software employees can install or which commands they can run, one interaction with one of these fake tools is enough to compromise an entire network.
What Gets Stolen and Where It Goes
RAT malware installed through ClickFix attacks is typically used to deploy infostealers — a category of malware specifically designed to extract credentials, session tokens, and sensitive files from the victim's machine. This data is packaged and sold through dark web markets and infostealer log communities, where other criminals purchase it to carry out account takeovers, business email compromise, and financial fraud.
Breachrr monitors these exact channels. When credentials from an infostealer dump surface in a dark web market, a hacker forum, or a leaked data collection, we flag it — so businesses know their data is exposed before an attacker uses it. The window between a credential being stolen and it being used is often short, which is why early detection matters.
Beyond credentials, RAT access can expose internal documents, client data, and financial records. That kind of exposure can trigger regulatory obligations and damage client trust, on top of the direct financial impact.
How to Reduce Your Exposure Right Now
The most effective first step is awareness. Brief your team on the ClickFix technique. Make it clear that no legitimate tool — AI or otherwise — will ever ask them to copy and paste a command into their keyboard as a "fix." That behaviour is always a red flag, regardless of how polished the interface looks.
Beyond awareness, tighten your endpoint controls. Restrict the ability to run unsigned scripts on work machines. Use application allowlisting where possible. And if your business uses AI tools, provide employees with a short approved list so they are not wandering toward convincing impostors.
Finally, assume that some credentials have already been compromised. Infostealer attacks often go undetected for weeks. Regular monitoring of breach databases, dark web dumps, and infostealer logs is the only way to know for certain. ClickFix attacks are evolving fast, and detection after the fact is still far better than never detecting exposure at all.
Run a free audit at breachrr.com/audit to see whether your business credentials are already circulating where they should not be.
Want to see if your company is exposed?