logo

Rogue CAPTCHAs: Look out for phony verification pages spreading malware

ID: c7f2f495-8426-511a-80fb-cd13123b6659

STIX ID: report--c7f2f495-8426-511a-80fb-cd13123b6659

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2025-07-24

Date Updated: 2026-05-01

...
...

This ESET article warns of a growing social-engineering vector—fake CAPTCHA verification pages (ClickFix)—used to trick users into executing clipboard-pasted commands that launch legitimate Windows tools (PowerShell, mshta.exe) to fetch and install malware. The scam has been used to deploy infostealers, remote access trojans, cryptominers and ransomware at scale; the piece explains why the technique works, examples of malicious behaviors, recommended user defenses (updates, reputable AV, ad blockers, MFA, password managers) and post-infection remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.