Rogue CAPTCHAs: Look out for phony verification pages spreading malware
ID: c7f2f495-8426-511a-80fb-cd13123b6659
STIX ID: report--c7f2f495-8426-511a-80fb-cd13123b6659
Feed Name: WeLiveSecurity (ESET Research)
This ESET article warns of a growing social-engineering vector—fake CAPTCHA verification pages (ClickFix)—used to trick users into executing clipboard-pasted commands that launch legitimate Windows tools (PowerShell, mshta.exe) to fetch and install malware. The scam has been used to deploy infostealers, remote access trojans, cryptominers and ransomware at scale; the piece explains why the technique works, examples of malicious behaviors, recommended user defenses (updates, reputable AV, ad blockers, MFA, password managers) and post-infection remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
