Logo

Imagine one of your staff is browsing the web, hits a page that says “Verify you’re human” or “Click to fix this download,” follows the on-screen instructions exactly as told, and within minutes a criminal on the other side of the world has their saved passwords, active login sessions, and copies of business documents from OneDrive and SharePoint. No suspicious attachment was opened, no obviously dodgy link was clicked. Just a few keystrokes that felt completely normal. This is the trick behind a scam technique security researchers call “ClickFix,” and it’s currently being used to spread a piece of malware called ACR Stealer that specifically targets Microsoft 365 accounts and browser data.

This matters for regional Victorian businesses because so many of us now run our entire operation through Microsoft 365 – email, invoicing, staff rosters, client files, accounting records. If one login gets compromised, an attacker doesn’t just see your inbox, they can potentially access shared drives, send emails as you to customers and suppliers, and quietly harvest sensitive documents for weeks before anyone notices.

How the ClickFix scam actually works

Unlike older phishing scams that rely on tricking someone into opening an infected attachment, ClickFix relies on a much simpler psychological trick: it convinces the victim to run the malicious command themselves. Typically it plays out like this:

  • A staff member visits a compromised website, clicks a fake software update, or opens a link from an email that looks legitimate.
  • A pop-up appears claiming there’s a problem – a broken CAPTCHA, a failed video player, a document that “won’t open properly.”
  • The pop-up gives step-by-step instructions: press a key combination, then paste something into the Windows “Run” box, then press Enter.
  • What gets pasted looks like gibberish to most people, but it’s actually a command that quietly downloads and installs malware in the background.

Because the victim is the one physically typing the commands, many antivirus tools and email filters never get a chance to intervene – there’s no attachment to scan and no obviously malicious link to block. As reported by The Hacker News, Microsoft’s own security team has traced two separate delivery methods using this exact approach to spread ACR Stealer, which then goes hunting for saved browser passwords, active login sessions (meaning it can potentially get into accounts even without knowing the password), PDFs, Microsoft 365 files, and anything synced through OneDrive or SharePoint.

Why small businesses are an attractive target

It’s tempting to assume this kind of attack is aimed at big corporations with valuable secrets to steal. In reality, small and medium businesses are frequently softer targets precisely because they tend to have fewer technical safeguards, no dedicated IT security staff watching for unusual activity, and staff who are juggling many roles and may not have had formal cyber awareness training. A stolen Microsoft 365 login from a regional business can be just as valuable to a criminal as one from a large company – it can be used to send convincing invoice fraud emails to real clients, access financial records, or simply be sold on to other criminals.

The other reason this scam works so well is that it doesn’t rely on tricking people with obviously dodgy emails anymore. Modern scam pages can look polished and professional, mimicking legitimate error messages that most people would never think twice about following.

What this looks like in practice

If a staff member sees a message telling them to “copy this code and paste it into the Run box to fix the issue,” that is one of the clearest warning signs of this scam. Legitimate software, websites, and IT support will almost never ask a user to manually paste commands into a system dialog box to solve a browser or website problem. If in doubt, the instruction should never be followed – instead, close the browser tab entirely and report it.

Practical steps to protect your business

The good news is that this type of attack can be defended against without a huge IT budget, mostly through a mix of staff awareness and some sensible technical settings.

  • Train staff to recognise the pattern. Make sure everyone in the business understands that being asked to copy and paste a command into a Windows dialog box is a major red flag, regardless of how convincing the surrounding page looks.
  • Turn on multi-factor authentication (MFA) for all Microsoft 365 accounts. This won’t stop every version of this attack (since some malware can steal active session tokens), but it significantly raises the bar and blocks many opportunistic attacks.
  • Restrict or monitor use of the Windows Run dialog and PowerShell where practical, particularly on machines used by staff who don’t need those tools for their day-to-day work.
  • Keep endpoint protection (antivirus/anti-malware) active and updated on every device, including personal laptops used for work if your business allows that.
  • Regularly review sign-in activity in Microsoft 365 for logins from unusual locations or at odd hours – this is often the first sign an account has been compromised.
  • Have a clear, simple reporting process so staff feel comfortable flagging something odd immediately, rather than trying to fix it themselves or staying quiet out of embarrassment.
  • Back up important files independently of OneDrive/SharePoint sync so that a compromised account doesn’t put your only copy of critical business documents at risk.

The bigger picture

Scams like ClickFix are a reminder that cybersecurity threats keep evolving to get around the defences businesses already have in place. A few years ago, staff training focused mainly on spotting dodgy email attachments and links. Now, criminals are finding new ways to get people to do the damaging step themselves, precisely because it slips past traditional filters. Regular, practical staff awareness training – even short refreshers every few months – remains one of the most cost-effective defences a small business can invest in, alongside the basic technical protections outlined above.

No single measure will stop every attack, but combining staff awareness, MFA, monitoring, and good backup practices creates layers of defence that make it much harder for an attacker to succeed – and much easier for your business to recover quickly if something does slip through.


Worried This Could Affect Your Business?

If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.

Book your free security assessment →

Logo
Servicing small businesses across the valley.
Get in touch
Customer Support

(+61) 0412 440 804

Copyright © 2025 Maximum IT Solutions