Stop ClickFix at the clipboard.
When a page copies an attack command, Secto blocks the page and replaces the command with safe text.
Animation: a fake human check copies a PowerShell command and tells the employee to paste it into Run. Secto replaces the clipboard with safe text and shows its "Unsafe clipboard content blocked" page.
How the attack works
Attackers get employees to run the payload themselves.
- 01The lure
It poses as a routine human check
ClickFix pages pose as a human check or an error to fix, on hacked sites and in ads.
- 02The copy
One click copies the command
The page then tells the employee to paste it and run it.
- 03No payload file
Existing controls see legitimate activity
There's no file to scan, only an employee running a command.
- 04At the copy
Secto takes the command off the clipboard
Secto spots the command after it is copied, blocks the page and puts safe text on the clipboard.
ClickFix defense
What Secto does.
- Detects
- Attack commands copied by a web page
- The employee sees
- A short notice, with safe text on the clipboard
- Your security team gets
- The page, the user and the browser
- Rollout
- Monitor first, then warn or block
Talk to the Secto team.
See Secto in action, from the policy console to the employee’s browser.
Frequently asked questions
Something else?
Talk to a security engineer about your browsers, identity provider and rollout.
Talk to our team- A page tricks someone into pasting and running a malicious command, usually disguised as a CAPTCHA.
- No. Copy and paste work as usual. Secto steps in only on attack commands.
- Yes. Give their group its own policy.