A cybercrime campaign known as **ClickFix** is currently spreading through compromised and malicious websites. Victims are presented with what appears to be a legitimate CAPTCHA or human verification prompt.
Instead of completing a normal verification, users are instructed to press **Windows + R**, **CTRL + V**, and **Enter**. These actions execute a malicious command that has been silently copied to the clipboard.
The command typically downloads an **information stealer** or other malware capable of stealing browser passwords, session cookies, email credentials, gaming accounts, cryptocurrency wallets, and other sensitive information. In some cases, attackers may also gain remote access to the affected device.
How to Protect Yourself
- Never execute commands requested by a website.
- Legitimate CAPTCHA services will never ask you to open Windows Run, PowerShell, or Command Prompt.
- Keep your operating system and security software up to date.
- Enable multi-factor authentication for important accounts.
- Change your passwords immediately if you executed such commands.
North Solutions Recommendation
North Solutions recommends closing any website that requests command execution as part of a verification process. Modern ClickFix campaigns rely on social engineering rather than software vulnerabilities, making user awareness the most effective defense.
