Technique
Fake Captcha
Also known as: ClickFix, FakeCAPTCHA, Clipboard Injection and Execution
Fake CAPTCHA (also known as ClickFix) is a social engineering technique where attackers present fraudulent CAPTCHA verification pages that trick users into executing malicious commands on their own systems. The attack exploits verification fatigue — users are so accustomed to completing CAPTCHAs tha…
Common attack flows
How it fits in a scam
Defense
How to defend against this
How to spot it
- Any website instructing you to press Win+R and paste something is malicious — legitimate CAPTCHAs never require system-level access
- Unexpected Run dialog or PowerShell window appearing after interacting with a CAPTCHA page
- CAPTCHA verification steps that seem unusually complicated or involve keyboard shortcuts beyond simple clicking
- Browser clipboard access notifications appearing on CAPTCHA-like pages
- Verification pages appearing in new tabs when clicking play buttons on streaming or pirated content sites
- Instructions mentioning 'verification hash' or asking you to paste text you did not write yourself
Seen in the wild
Where we’ve seen it
Commonly targets
Further reading
Microsoft Security Blog
Comprehensive analysis of ClickFix social engineering technique by Microsoft Threat Intelligence and Defender Experts, including attack chains, malvertising delivery, and thousands of affected devices per month.
Yahoo Tech / ESET
Reports ESET 2025 threat report finding of 517% surge in ClickFix attacks, making it the second most common attack method after phishing.
Malwarebytes Blog
Analysis of fake CAPTCHA clipboard hijacking mechanism and infostealer delivery targeting consumers.
Splunk Security Blog
Technical detection analysis including PowerShell command patterns, clipboard manipulation JavaScript, and detection signatures for FakeCAPTCHA/ClickFix attacks.
SentinelOne Blog
Analysis of ClickFix weaponizing verification fatigue to deliver Lumma Stealer, NetSupport RAT, and SectopRAT.
Kaspersky Blog
Consumer-oriented explanation of ClickFix technique including five common pretexts: browser errors, document failures, email issues, video conference problems, and fake CAPTCHAs.
Palo Alto Unit 42
Technical analysis of ClickFix attack vector including ClearFake infrastructure redirecting compromised website visitors to fake verification pages.
Arsen Blog
Documents 517% surge per ESET telemetry and recent campaigns targeting Microsoft, Cloudflare, and crypto users including LinkedIn-based social engineering with spoofed Cloudflare CAPTCHAs.