Microsoft warns of 'ClickFix' malware disguised as fake CAPTCHA tests

No legitimate security check asks you to run hidden commands
Microsoft warns that any request to paste commands into Windows Run is a sign of malicious intent.
Mark

So the core trick here is that the malware is already sitting on your computer before you even paste the command?

Mimi

Exactly. The compromised website pre-loads it into your browser's cache, disguised as an image file. When you paste the command, you're not downloading anything new—you're just telling your computer to find that hidden file and run it.

Luke

But how does the user end up on a compromised website in the first place? Is this a targeted attack or are we talking about legitimate sites that have been hacked?

Mimi

The source doesn't specify whether these are legitimate sites that attackers have compromised or sites set up specifically for this campaign. That's actually an important distinction.

Mark

And once the script runs, what exactly can the attacker do?

Mimi

They can steal your browser passwords, grab personal credentials, and set up persistent backdoor access so they keep control even after you restart your computer.

Luke

The source mentions PowerShell and WMI as the tools the malware uses. Are those Windows features that most users have no idea they're running?

Mimi

Yes. They're built into Windows and designed for legitimate system administration. The malware just repurposes them.

Mark

So the defense really does come down to never pasting commands into Run or Command Prompt, no matter what?

Mimi

That's the golden rule. If someone asks you to do that, it's malicious. Full stop.

Luke

What about users who genuinely don't know the difference between a fake CAPTCHA and a real one? The source says these are becoming more convincing.

Mimi

That's the vulnerability Microsoft is trying to close—user education. But it's an uphill battle because the fake ones do look legitimate.

  • Attackers have weaponized the CAPTCHA — one of the internet's most trusted rituals — transforming a routine human-verification step into a mechanism for handing over full administrative control of a Windows machine.
  • The scheme bypasses antivirus software entirely by pre-loading malware disguised as an image file in the browser cache before the user ever clicks anything suspicious.
  • Once a victim pastes the hidden command into the Windows Run dialog, a silent chain reaction unfolds: PowerShell scripts execute, credentials are harvested, and persistent backdoors are embedded deep in system settings.
  • Microsoft and security administrators are racing to deploy layered defenses — SmartScreen filters, network monitoring, script-logging — but the attack's greatest exploit remains human habit, not hardware.
  • The clearest protection available today is a single rule: no legitimate service, institution, or support team will ever ask you to paste a command into your own operating system to complete a security check.

In an age when digital trust is both currency and vulnerability, Microsoft has identified a campaign that turns the mundane ritual of proving one's humanity online into a doorway for machine compromise. The so-called ClickFix attack does not overpower its victims through technical sophistication — it persuades them, borrowing the visual grammar of legitimate security to guide users into surrendering control of their own computers. The lesson it carries is ancient: the most effective deceptions do not look like deceptions at all.

Microsoft has identified a quietly dangerous attack that exploits one of the internet's most familiar interactions: the CAPTCHA verification test. Researchers call it ClickFix, and its power lies not in complexity but in misdirection — it hides malicious intent behind the visual language of routine security that users have been conditioned to trust without hesitation.

The trap is set when a user visits a compromised website. A convincing fake verification window appears, but instead of processing within the browser, it instructs the user to copy a block of text, open the Windows Run dialog with a keyboard shortcut, paste the command, and press Enter. To the uninitiated, it resembles a standard IT troubleshooting step. In practice, it transfers administrative control of the machine directly to the attacker.

What makes ClickFix especially effective is how it sidesteps conventional antivirus defenses. Before the user interacts with the fake prompt, the compromised site has already quietly deposited a malicious script into the browser's temporary storage, camouflaged as a harmless image file. When the pasted command executes, it locates this hidden file, renames it into a runnable script, and launches it silently — leaving no download trail for security software to detect.

The malware then conducts a methodical takeover. Using built-in Windows tools like PowerShell and Windows Management Instrumentation, it maps the system, loads harmful code into temporary memory to avoid detection, extracts stored passwords and browser credentials, and schedules hidden background tasks that survive a full system restart.

Microsoft recommends combining technical defenses — Defender SmartScreen, cloud protection, network monitoring, and script-logging — with something no software can fully replace: informed human judgment. The rule is simple and absolute. No legitimate security service will ever ask a user to paste commands into a Run dialog, Command Prompt, or Terminal. Any prompt that does should be treated as an immediate warning sign. ClickFix succeeds because it borrows the appearance of safety. Recognizing that legitimate security never asks you to leave the browser is, for now, the most reliable defense available.

Microsoft has identified a deceptively simple attack that exploits something most internet users encounter without thinking twice: the CAPTCHA verification test. The threat, which researchers call ClickFix, weaponizes the muscle memory people develop from years of clicking boxes and identifying street signs to prove they're human. What makes it dangerous is not complexity but misdirection—the attackers have learned to hide malicious intent behind the familiar face of routine security.

The attack begins when a user lands on a compromised website. Instead of loading normally, a fake verification window appears, visually indistinguishable from legitimate security checks. But this is where the trap diverges from what users expect. Rather than processing the verification within the browser itself, the fraudulent prompt instructs the victim to copy a block of text, open the Windows Run dialog by pressing Windows Key + R, paste the command, and hit Enter. To someone unfamiliar with how these systems actually work, it reads like a standard troubleshooting step—the kind of thing an IT support person might ask you to do over the phone. In reality, it hands administrative control of the computer directly to the attacker.

What makes ClickFix particularly effective is how it circumvents the security layers most people rely on. Traditional antivirus software monitors the internet for suspicious file downloads, but this attack bypasses that checkpoint through a two-stage maneuver. First, before the user even interacts with the fake CAPTCHA, the compromised website secretly downloads a malicious script into the browser's temporary storage, disguising it as a harmless image file with a .PNG extension. Then, when the victim pastes the command into the Run box, that command doesn't need to download anything new. Instead, it searches the hard drive for the hidden file, renames it into an executable script, and launches it silently in the background. The entire operation leaves no download trail for security software to catch.

Once the script runs, it begins a methodical takeover of the infected system. It deploys built-in Windows tools like PowerShell and Windows Management Instrumentation to map out the system's configuration and retrieve additional malicious payloads. The malware then establishes multiple layers of persistence. It loads harmful code directly into the computer's temporary memory rather than writing to the hard drive, making it harder to detect. It targets stored passwords and credentials from web browsers, extracting sensitive personal data. And critically, it modifies system settings and schedules hidden background tasks to ensure that even if the user restarts their computer, the attacker maintains access.

Microsoft recommends a layered defense combining security software and user awareness. Built-in protections like Microsoft Defender SmartScreen and Defender for Endpoint can block known malicious sites and flag suspicious ClickFix behavior. IT administrators are advised to enable cloud-delivered protection, web protection, network monitoring, and script-logging to catch abnormal command activity. But the most reliable safeguard remains human judgment. No legitimate security service—not Microsoft, not your bank, not any official IT support team—will ever ask you to copy and paste commands into the Windows Run dialog, Command Prompt, PowerShell, or Terminal. Any request to do so should be treated as an immediate red flag. The attack succeeds because it exploits trust in familiar processes. Staying safe means recognizing that legitimate security checks never ask you to leave the browser and run hidden commands on your machine.

Any request asking you to copy and paste commands into your Windows Run dialog should immediately be treated as a malicious attack
— Microsoft security guidance
Envie de l'histoire complète ? Lire l'original sur Yahoo Tech ↗
Nous contacter FAQ