logo

Fake CAPTCHA tests trick users into running malware

ID: 58759ac7-1ba9-5182-a463-7781f486b35d

STIX ID: report--58759ac7-1ba9-5182-a463-7781f486b35d

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-08-22

Date Updated: 2026-04-26

Author: Gareth Halfacree

...
...

Microsoft details the ClickFix social-engineering technique that fools users into pasting and executing attacker-supplied commands (often via a fake CAPTCHA) to install malware; campaigns have delivered high-impact payloads such as Lumma Stealer, Lampion, various RATs, loaders, and rootkits against enterprise and government targets, with observed global scale and included indicators of compromise and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.