Stop ClickFix at the clipboard.

When a page copies an attack command, Secto blocks the page and replaces the command with safe text.

See how it happens

Animation: a fake human check copies a PowerShell command and tells the employee to paste it into Run. Secto replaces the clipboard with safe text and shows its "Unsafe clipboard content blocked" page.

How the attack works

Attackers get employees to run the payload themselves.

  1. 01
    The lure

    It poses as a routine human check

    ClickFix pages pose as a human check or an error to fix, on hacked sites and in ads.

  2. 02
    The copy

    One click copies the command

    The page then tells the employee to paste it and run it.

  3. 03
    No payload file

    Existing controls see legitimate activity

    There's no file to scan, only an employee running a command.

  4. 04
    At the copy

    Secto takes the command off the clipboard

    Secto spots the command after it is copied, blocks the page and puts safe text on the clipboard.

ClickFix defense

What Secto does.

Detects
Attack commands copied by a web page
The employee sees
A short notice, with safe text on the clipboard
Your security team gets
The page, the user and the browser
Rollout
Monitor first, then warn or block

Talk to the Secto team.

See Secto in action, from the policy console to the employee’s browser.

Visit the Trust Center

Frequently asked questions

Something else?

Talk to a security engineer about your browsers, identity provider and rollout.

Talk to our team
  • A page tricks someone into pasting and running a malicious command, usually disguised as a CAPTCHA.