• Overview
    • Scam Map
    • Kill Chain
Recents

    Conversations will appear here

Technique

Fake Captcha

Also known as: ClickFix, FakeCAPTCHA, Clipboard Injection and Execution

DELIVERY

Fake CAPTCHA (also known as ClickFix) is a social engineering technique where attackers present fraudulent CAPTCHA verification pages that trick users into executing malicious commands on their own systems. The attack exploits verification fatigue — users are so accustomed to completing CAPTCHAs tha…

Common attack flows

How it fits in a scam

This technique shows up duringDELIVERY

Before

  • MalvertisingDELIVERY
  • SEO PoisoningDELIVERY

After

  • InfostealerCOMPROMISE
  • Credential TheftCOMPROMISE
  • Remote Access ToolPERSISTENCE
  • Crypto Wallet DrainMONETIZATION

Defense

How to defend against this

How to spot it

  • Any website instructing you to press Win+R and paste something is malicious — legitimate CAPTCHAs never require system-level access
  • Unexpected Run dialog or PowerShell window appearing after interacting with a CAPTCHA page
  • CAPTCHA verification steps that seem unusually complicated or involve keyboard shortcuts beyond simple clicking
  • Browser clipboard access notifications appearing on CAPTCHA-like pages
  • Verification pages appearing in new tabs when clicking play buttons on streaming or pirated content sites
  • Instructions mentioning 'verification hash' or asking you to paste text you did not write yourself

Tools you can use

  • Antivirus SoftwareCost low · Effect medium
  • Ad BlockerCost low · Effect high
  • DNS FilteringCost low · Effect high
  • Browser Security ExtensionCost low · Effect medium

Steps you can take

  • Avoid Pirated SoftwareCost low · Effect high

Seen in the wild

Where we’ve seen it

Commonly targets

  • Gamer

Further reading

  • Microsoft Security Blog

    Comprehensive analysis of ClickFix social engineering technique by Microsoft Threat Intelligence and Defender Experts, including attack chains, malvertising delivery, and thousands of affected devices per month.

  • Yahoo Tech / ESET

    Reports ESET 2025 threat report finding of 517% surge in ClickFix attacks, making it the second most common attack method after phishing.

  • Malwarebytes Blog

    Analysis of fake CAPTCHA clipboard hijacking mechanism and infostealer delivery targeting consumers.

  • Splunk Security Blog

    Technical detection analysis including PowerShell command patterns, clipboard manipulation JavaScript, and detection signatures for FakeCAPTCHA/ClickFix attacks.

  • SentinelOne Blog

    Analysis of ClickFix weaponizing verification fatigue to deliver Lumma Stealer, NetSupport RAT, and SectopRAT.

  • Kaspersky Blog

    Consumer-oriented explanation of ClickFix technique including five common pretexts: browser errors, document failures, email issues, video conference problems, and fake CAPTCHAs.

  • Palo Alto Unit 42

    Technical analysis of ClickFix attack vector including ClearFake infrastructure redirecting compromised website visitors to fake verification pages.

  • Arsen Blog

    Documents 517% surge per ESET telemetry and recent campaigns targeting Microsoft, Cloudflare, and crypto users including LinkedIn-based social engineering with spoofed Cloudflare CAPTCHAs.

Related techniques

Same stage

  • Phishing Email
  • Smishing
  • Vishing
  • Deepfake Voice Call
  • SEO Poisoning
  • +16 more

Similar defense

  • Remote Access Tool
  • Clipboard Hijacking
  • Malicious App Installation
  • Supply Chain Compromise
  • Ad Network Tracking
  • +11 more