{"id":2929,"date":"2025-03-29T10:05:43","date_gmt":"2025-03-29T10:05:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/29\/clickfix-captcha-a-creative-technique-that-allow-attackers-deliver-malware-and-ransomware-on-windows\/"},"modified":"2025-03-29T10:05:43","modified_gmt":"2025-03-29T10:05:43","slug":"clickfix-captcha-a-creative-technique-that-allow-attackers-deliver-malware-and-ransomware-on-windows","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/29\/clickfix-captcha-a-creative-technique-that-allow-attackers-deliver-malware-and-ransomware-on-windows\/","title":{"rendered":"ClickFix Captcha \u2013 A Creative Technique That Allow Attackers Deliver Malware and Ransomware on Windows"},"content":{"rendered":"<p>    ClickFix Captcha \u2013 A Creative Technique That Allow Attackers Deliver Malware and Ransomware on Windows<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated social engineering technique has recently emerged in the cybersecurity landscape, rapidly gaining traction among threat actors seeking to distribute trojans, ransomware, and particularly Quakbot malware.<\/p>\n<p>This technique, known as ClickFix Captcha, exploits users\u2019 trust in familiar web elements to bypass traditional security measures and deliver malicious payloads to Windows systems.<\/p>\n<p>The attack begins when users visit compromised or malicious websites that redirect them to a seemingly legitimate captcha verification page at domains such as cfcaptcha[.]com.<\/p>\n<p>Unlike traditional captchas that require users to identify objects or type text, ClickFix captchas instruct users to perform specific actions on their computers, such as pressing Windows key + R, claiming this will verify they aren\u2019t bots.<\/p>\n<p>Dark Atlas researchers <a href=\"https:\/\/darkatlas.io\/blog\/delivering-trojans-via-clickfix-captcha\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">detected<\/a> that when users follow these instructions, they unwittingly execute malicious commands that have been preloaded into their clipboard.<\/p>\n<p>The researchers noted the commands typically invoke <a href=\"https:\/\/cybersecuritynews.com\/exploitation-of-exchange-powershell\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> to download and execute additional malicious code while displaying deceptive \u201cVerification complete\u201d messages to maintain the illusion of legitimacy.<\/p>\n<p>The infection chain is particularly insidious because it leverages common Windows functionality rather than exploiting technical vulnerabilities.<\/p>\n<p>When users press Windows key + R after interacting with the captcha, they open the Run dialog, and the <a href=\"https:\/\/cybersecuritynews.com\/cisco-nexus-vulnerability-malicious-commands\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious command<\/a> in their clipboard is automatically inserted.<\/p>\n<p>One keystroke later, the system is compromised.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Advanced Infection Mechanism<\/strong><\/h2>\n<p>The technical sophistication of this attack lies in its multi-stage execution process.<\/p>\n<p>Upon execution, the clipboard-injected command typically contains obfuscated PowerShell code that downloads a remote file.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjCjAZluj2UDIQKcVLRZ39P7NhKroC87zNJy-sTre7kf42uIuGYL01biWQfTz4nnrfwB6sucZEyJUf0vJnzg4ll9sr1IW7k1ZDhP4Mrvq9CmoWjsBsUJutM-kUlF_xDenKVCO5YkIUJfe58dVcaQRxEt48e3YkhjDhdVSVLKumPmz0snczNaobN_WCodYw\/s16000\/PowerShell%2520command%2520that%2520executes%2520the%2520retrieved%2520string%2520as%2520a%2520PowerShell%2520command%2520%28Source%2520-%2520Dark%2520Atlas%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">PowerShell command that executes the retrieved string as a PowerShell command (Source \u2013 Dark Atlas)<\/figcaption><\/figure>\n<\/div>\n<p>This initial payload displays a <a href=\"https:\/\/cybersecuritynews.com\/fake-captcha-malware-attacking-windows-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">fake verification<\/a> message while silently downloading additional components from attacker-controlled domains like duolingos[.]com.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgTjlY1GxbXAqeCNM2ROqUmKbv6KMlvZrffqfSrZw5RokIoGm2IgAovSPuZT8LnfaFvaELYCvDjIBUxl5B081ZncG21F49Dg7r_z80pYeiNkEA-Bho0hXzb3eQvcsr_zKl2FYdo0Khjc94_r6kQTufeUiP5_lNLSFF5eC7MXyIF2CfdIivIT2mI8FXbpCw\/s16000\/Attacker-controlled%2520domain%2520%28Source%2520-%2520Dark%2520Atlas%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Attacker-controlled domain (Source \u2013 Dark Atlas)<\/figcaption><\/figure>\n<\/div>\n<p>Analysis of the malicious code revealed XOR encryption techniques designed to evade detection. The decrypted payload contains instructions to download and extract ZIP files to the user\u2019s AppData directory.<\/p>\n<p>One captured example showed commands to retrieve \u201cflswunwa.zip\u201d and extract its contents, which would then establish persistence and potentially exfiltrate sensitive data.<\/p>\n<p>What makes ClickFix particularly dangerous is the attackers\u2019 implementation of rewrite rules and PHP-based proxies on compromised servers, allowing them to generate unlimited unique URLs for malware distribution while concealing the actual origin of the malicious content.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/clickfix-captcha-a-creative-technique\/\">ClickFix Captcha \u2013 A Creative Technique That Allow Attackers Deliver Malware and Ransomware on Windows<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/clickfix-captcha-a-creative-technique\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>ClickFix Captcha \u2013 A Creative Technique That Allow Attackers Deliver Malware and Ransomware on Windows A sophisticated social engineering technique has recently emerged in the cybersecurity landscape, rapidly gaining traction among threat actors seeking to distribute trojans, ransomware, and particularly Quakbot malware. This technique, known as ClickFix Captcha, exploits users\u2019 trust in familiar web elements [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-2929","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2929"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2929"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2929\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}