logo

Fake CAPTCHA Scam Tricks Windows Users Into Installing Malware

ID: 10650c5e-fc90-5eed-98ed-35ad332c0cac

STIX ID: report--10650c5e-fc90-5eed-98ed-35ad332c0cac

Feed Name: TechRepublic Security

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-23

Author: Ken Underhill

...
...

The report details a ClickFix campaign where compromised legitimate websites display convincing Cloudflare-like CAPTCHA pages that instruct users to paste and run a PowerShell command; this clipboard-based trick executes a multi-stage, largely in-memory chain (Donut-generated shellcode, reflective loading, a VC++ downloader and injection into svchost.exe) to deploy the StealC info-stealer which exfiltrates browser credentials, crypto wallets, Steam/Outlook accounts and screenshots over RC4-encrypted HTTP. The article recommends detection and mitigation measures including monitoring for fileless behaviors and encoded PowerShell, hardening PowerShell execution, applying application control (WDAC/AppLocker), monitoring outbound traffic for C2 indicators, and reducing endpoint credential exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.