NORTHSOLUTIONS Subscribe
DE/EN
Knowledge/Scam alerts
high

ClickFix: Fake CAPTCHA Prompts Used to Install Malware

Cybercriminals are using fake CAPTCHA prompts to trick users into executing malicious Windows commands, leading to malware infections and credential theft.

STAY INFORMED ABOUT IMPORTANT CHANGES

Follow this article.

You will receive an email when, for example, an official fix is added or the status changes to “Resolved”.

Follow article

A cybercrime campaign known as **ClickFix** is currently spreading through compromised and malicious websites. Victims are presented with what appears to be a legitimate CAPTCHA or human verification prompt.

Instead of completing a normal verification, users are instructed to press **Windows + R**, **CTRL + V**, and **Enter**. These actions execute a malicious command that has been silently copied to the clipboard.

The command typically downloads an **information stealer** or other malware capable of stealing browser passwords, session cookies, email credentials, gaming accounts, cryptocurrency wallets, and other sensitive information. In some cases, attackers may also gain remote access to the affected device.

How to Protect Yourself

  • Never execute commands requested by a website.
  • Legitimate CAPTCHA services will never ask you to open Windows Run, PowerShell, or Command Prompt.
  • Keep your operating system and security software up to date.
  • Enable multi-factor authentication for important accounts.
  • Change your passwords immediately if you executed such commands.

North Solutions Recommendation

North Solutions recommends closing any website that requests command execution as part of a verification process. Modern ClickFix campaigns rely on social engineering rather than software vulnerabilities, making user awareness the most effective defense.