Bleepingcomputer Opera Launches Paste Protect to Combat ClickFix Attacks
Article Content
- •Paste Protect is a new feature in Opera to prevent clipboard-based attacks.
- •The feature blocks ClickFix-style attacks, which trick users into executing malicious commands.
- •Enabled by default, Paste Protect uses Hijack Protection and Injection Protection mechanisms.
On July 2, 2026, Opera introduced a new security feature called Paste Protect to prevent clipboard hijacking and code injection attacks, specifically targeting ClickFix-style attacks. These attacks trick users into copying and executing malicious commands, often through deceptive prompts on compromised websites. Paste Protect is enabled by default in Opera's browser, providing proactive protection without user configuration. The feature integrates Hijack Protection, which prevents unauthorized modifications of clipboard content, and a new Injection Protection mechanism that blocks harmful commands before they can be copied. This initiative comes in response to the rising prevalence of ClickFix attacks, which accounted for over 53% of malware loader activity in 2025. Users are notified of blocked actions with contextual alerts, and advanced options allow for whitelisting trusted domains. The feature supports Windows, macOS, and Linux systems, enhancing user security across platforms.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Following this threat?
Track ClickFix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
New ChainScript RAT Exploits ClickFix Lures with Blockchain C2 A newly discovered Node.js remote access trojan (RAT) named ChainScript is being deployed through ClickFix social engineering tactics, targeting Windows systems. The malware utilizes a unique command-and-control (C2) discovery method by querying a Polygon blockchain smart contract to dynamically rotate its server…
Cybercriminals Exploit ChatGPT Custom GPTs for ClickFix RAT Attacks A new ClickFix campaign has been discovered that exploits ChatGPT Custom GPTs to impersonate legitimate products, luring users into executing malicious code. Cybersecurity firm Huntress reported that at least 40 users have been infected, with two confirmed incidents linked to Custom GPT instances. The attackers…