Fake ClickFix attacks are using realistic Windows Update screens to trick victims into running malicious commands that install the Rhadamanthys credential-stealing malware. The campaign hides its payload through steganography inside PNG images, allowing the malware to bypass detection. Huntress linked over 76 global incidents, and experts urge organizations to block Run commands and train users to avoid Copy-and-Paste “fixes.”