logo

CAPTCHA and ClickFix Abuse Fuels Credential Theft Surge

ID: e4c46e17-a59a-5bbc-a26b-866b435ff8c9

STIX ID: report--e4c46e17-a59a-5bbc-a26b-866b435ff8c9

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Mayura Kathir

...
...

Microsoft threat intelligence observed a large, active surge in hosted credential-phishing campaigns in Q1 2026, highlighting rapid growth in QR-code phishing, CAPTCHA-gated pages, and ClickFix-style command-paste tricks that bypass traditional attachment scanning. The report documents ~8.3 billion email-based phishing threats for the quarter, spikes to ~11.9M CAPTCHA-gated attacks and ~18.7M QR-code attacks in March, the resilience of PhaaS platforms like Tycoon2FA, and recommends layered email and identity defenses including phishing-resistant MFA, conditional access, and targeted user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.