This sneaky malware variant has been caught using fake Windows Update screens to trick users into installing info-stealing software themselves

A photo of the Windows update menu, showing that I'm all up to date
(Image credit: Future)

If you're anything like me, you keep a sharp eye on your Windows Defender updates to make sure your PC is protected against the latest threats. However, while Defender is remarkably good at catching dodgy files these days, it can't do a whole lot about users bypassing its security methods themselves, if convinced to do so.

Which is precisely what a new variant of known malware ClickFix has been caught doing: Tricking users into thinking that an innocent Windows Update requires them to paste a malicious command into the Run window (via Bleeping Computer). Researchers at security services provider Huntress have detailed the novel new method in a blog post, and it's quite the feat of social engineering.

A computer screen with program code warning of a detected malware script program. 3d illustration

(Image credit: solarseven, via Getty Images)

Huntress goes into more detail as to exactly how a dodgy .png file can be used to inject malware into your system, but if I were to explain it all here, I'd need eight more paragraphs and quite possibly a short nap. It's a very novel approach, put it that way, but it's the social engineering aspect of this particular "lure" that has me intrigued.

After all, I'm forever telling my friends and relatives to keep Windows updated as a best security practice, but I can't do a whole lot to protect the less vigilant of them from falling for a relatively convincing fake.

As a final PSA, though, I'd say that Windows Update should never ask you to interact with any system processes yourself, and you also shouldn't accept free candy from strangers. That oughta do it, don't you think?

Secretlab Titan Evo gaming chair in Royal colouring, on a white background
Best PC gaming kit 2025

1. Best gaming chair: Secretlab Titan Evo

2. Best gaming desk: Secretlab Magnus Pro XL

3. Best gaming headset: Razer BlackShark V3

4. Best gaming keyboard: Asus ROG Strix Scope II 96 Wireless

5. Best gaming mouse: Razer DeathAdder V4 Pro

6. Best PC controller: GameSir G7 Pro

7. Best steering wheel: Logitech G Pro Racing Wheel

8. Best microphone: Shure MV6 USB Gaming Microphone

9. Best webcam: Elgato Facecam MK.2


👉Check out our list of guides👈

Andy Edser
Hardware Writer

Andy built his first gaming PC at the tender age of 12, when IDE cables were a thing and high resolution wasn't—and he hasn't stopped since. Now working as a hardware writer for PC Gamer, Andy spends his time jumping around the world attending product launches and trade shows, all the while reviewing every bit of PC gaming hardware he can get his hands on. You name it, if it's interesting hardware he'll write words about it, with opinions and everything.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.