You search for something on Google. The first result looks right, familiar brand name, clean URL, top of the page. You click it. The page asks you to complete a quick step to continue.
If you follow those instructions, malware is already running on your computer by the time you realize something is wrong.
This is GoogleFix, a variant of the ClickFix attack family that uses Google's own advertising infrastructure as its delivery mechanism. It was first documented by researchers at Guardio Labs in March 2026. Unlike attacks that require compromising a website, GoogleFix doesn't need to hack anything. It buys its way in.
How GoogleFix works
ClickFix and ClearFake traditionally spread through compromised websites. GoogleFix skips that step entirely, it purchases sponsored placements in Google Search, targeting users actively looking for software to download.
- You search for something on Google. The attacker has bid on relevant keywords through Google Ads, software names, app downloads, productivity tools.
- A sponsored result appears at the top. It looks legitimate: a recognizable brand name, a professional description, a plausible URL.
- The lure page asks you to complete a step. A "verification" or "installation" prompt appears. Some variants mimic browser setup pages, others fake a stalled download.
- It silently writes a malicious command to your clipboard. JavaScript copies a PowerShell or terminal command without any visible sign.
- It tells you to paste and run it. You're directed to open Run (Win+R) or Terminal and paste. It's framed as a required setup step.
- The command executes. Guardio Labs found that macOS-targeted campaigns typically install AMOS, Atomic macOS Stealer, which extracts saved passwords, iCloud Keychain data, crypto wallet contents, and session cookies.
No software vulnerability required. The whole sequence takes under a minute.
Why it's called GoogleFix
The name was coined by Guardio Labs in their March 2026 research. They named it GoogleFix because it combines the "Fix" social engineering pattern, a fake problem that requires a fake fix, with Google's sponsored search results as the delivery method.
Why traditional security misses it
- The result looks real. Sponsored placements have the same formatting as organic results. There's no visual signal something is wrong.
- The domain may pass reputation checks. Attackers register convincing-looking domains, or use pages on legitimate platforms that can't be blocklisted.
- No file exists until after you act. Antivirus scans files. The clipboard payload is invisible until you paste and run it.
- You initiated the action. From the OS perspective, a user opened Run, typed a command, and pressed Enter. That's normal behavior.
By the time any tool could flag something, the malware has already run.
Who is being targeted
Because attackers pay per click, GoogleFix campaigns tend to focus on high-value search terms: software downloads, developer tools, productivity apps. macOS users are disproportionately targeted, they're seen as higher-value credentials and may be less familiar with clipboard-based attacks.
That said, anyone who searches Google, clicks a sponsored result, and follows on-screen instructions is a potential target.
How to protect yourself
Know the red flags
No legitimate software installer asks you to open Run or Terminal. Any page that does, regardless of how you got there, is suspicious. "Verification" steps involving Win+R or Ctrl+V are attack patterns, not real security checks.
Check what you're clicking
Before clicking a sponsored result for software, go to the official website directly. Attackers register domains designed to look plausible at a glance, small misspellings, extra words, different TLDs.
Use browser-level protection
GoogleFix operates entirely inside the browser. Intersafe detects when a page attempts to silently write a command to your clipboard and blocks it before it gets there. All detection runs locally.
Be skeptical of urgency
Legitimate software doesn't require you to paste commands to get started. If a step feels unusual, it is.
GoogleFix is evolving
Since Guardio Labs' original report, the same trusted-platform delivery approach has spread:
- AI platform lures. Attackers now publish malicious "install guides" as shared conversations on ChatGPT and Claude, real URLs on real domains that pass every reputation check.
- macOS Terminal variants. Commands instruct Mac users to open Terminal and paste a command that silently downloads and mounts a malware disk image using Apple's own
hdiutilutility.
The defining pattern across all variants: use a trusted channel to make the lure feel legitimate, then present the clipboard instruction.
What to do if you've been hit
- Disconnect from the internet immediately
- Run a full antivirus scan
- Change your passwords from a clean device, start with email and banking
- Check for unauthorized access, unfamiliar logins, transactions you don't recognize
- Enable two-factor authentication on all important accounts
Info-stealers transmit data within seconds of execution. Act fast.
The bigger picture
What makes GoogleFix significant isn't the technique, clipboard-and-paste social engineering isn't new. What's significant is the delivery channel. Earlier attacks needed to compromise a website first. GoogleFix demonstrated you can rent access to Google's infrastructure for a few dollars per click and reach users who are actively looking to download something. The red flag isn't on the page. It's in the instruction to paste something into a command line.
Stay skeptical of any page that asks you to run something, regardless of how you got there.
Intersafe detects and blocks GoogleFix, ClickFix, ClearFake, and similar attacks automatically. Free, private, and built for exactly this.
Add Intersafe to your browserIntersafe protects the browser on your computer, not your phone. Send yourself the link and open it there.