ClickFix attacks take advantage of fake CAPTCHA, committed legitimate sites and commands that victims themselves run on Windows or macOS. The strategy reduces costs for criminals, circumvents some traditional defenses and also finds new routes through online public documents.