NEWS

ClickFix: New CAPTCHA Scam Delivers Malware

A new scam dubbed “ClickFix” weaponizes fake Cloudflare CAPTCHAs, tricking users into unknowingly executing malicious commands via clipboard injection. This sophisticated social engineering attack bypasses traditional defenses, delivering potent malware like info-stealers and RATs.

By
LNGFRM Team
Published June 9, 2025
Dark gray mouse cursor impacting a grid of gray squares, causing jagged cracks to splinter across the surface.
Illustration by Addison Smith for LNGFRM

In the relentless cat-and-mouse game of cybersecurity, a new and particularly cunning predator has emerged, turning our very attempts at digital diligence against us.

Dubbed “ClickFix,” this sophisticated scam weaponizes the mundane, transforming the ubiquitous Cloudflare CAPTCHA — that familiar little box we tick to prove our humanity — into a silent gateway for malware.

It’s a stark reminder that in the digital realm, familiarity can breed contempt, and in this case, compromise.

The insidious genius of ClickFix lies not in its technical complexity, but in its psychological precision.

We have all encountered Cloudflare’s Turnstile CAPTCHA pages, designed to filter out bots and ensure we are, indeed, human.

The security padlock, the reassuring “Verify you are human” button, the unique Ray ID — these elements have become ingrained signals of safety and legitimacy.

ClickFix meticulously replicates every single one of them.

From the visual layout to the seemingly innocuous technical identifiers, the fake page is a mirror image of the real thing, crafted to lull users into a false sense of security.

This isn’t just a clever mimicry; it’s an exploitation of what security researchers term “verification fatigue.”

In an age saturated with security prompts, pop-ups, and checkboxes, our natural inclination is to click through them with minimal scrutiny.

We’ve been conditioned to trust these digital gatekeepers, to instinctively comply with their requests.

ClickFix preys on this learned behavior, transforming a routine security check into a Trojan horse.

The attack unfolds with deceptive simplicity.

A user, perhaps redirected from a compromised or cleverly spoofed website, lands on the counterfeit Cloudflare page.

They are prompted to tick the “Verify you are human” box.

So far, so normal.

But what follows is the core of the scam: instead of a traditional challenge, the page presents a set of seemingly harmless instructions: press Win+R, then Ctrl+V, and finally Enter.

These keyboard commands, which appear to be part of a legitimate verification process, silently execute a PowerShell command that has already been injected into the user’s clipboard without their knowledge.

Once executed, this command doesn’t just verify humanity; it retrieves a payload of malicious software.

We’re talking about potent threats like Stealc, a notorious information stealer, Lumma, another formidable data exfiltrator, or even remote access trojans (RATs) such such as NetSupport Manager, which grant attackers full control over the compromised machine.

The implications are chilling: stolen credentials, financial data, personal files, or even the complete hijacking of your device, turning it into a zombie in a botnet.

What makes ClickFix especially difficult to counter with traditional defenses is its method of delivery.

It doesn’t rely on exploiting software vulnerabilities or tricking users into downloading executable files.

Instead, it leverages legitimate Windows utilities and social engineering, turning the user into the unwitting accomplice.

Standard antivirus software and endpoint protection solutions, typically geared towards detecting suspicious downloads or binaries, are often blind to this method because the user themselves initiates the malicious command.

The phishing page itself is delivered as a single HTML file, yet it contains embedded scripts and obfuscated code designed specifically for this clipboard injection trick.

This cunning evasion strategy highlights a critical shift in the threat landscape.

As Daniel Kelley, a security researcher, aptly puts it, “ClickFix is a social engineering attack that tricks users into running malicious commands on their own devices – all under the guise of a routine security check.”

It’s not about a technical flaw in a system; it’s about a psychological flaw in human interaction with technology.

And while the PowerShell command targets Windows machines, the initial browser-based redirection can ensnare users across macOS, Android, and iOS devices, making it a truly cross-platform threat.

The lessons from ClickFix are profound.

We can no longer afford to blindly trust the familiar.

Every security prompt, every seemingly routine step, must be approached with a healthy dose of skepticism.

The digital world is evolving, and with it, the nature of threats.

The emphasis is moving from exploiting obscure code vulnerabilities to leveraging our ingrained habits and trust.

This demands a new level of digital literacy, a heightened awareness that the lines between legitimate security and malicious deception are blurring at an alarming rate.

For individuals, the defense begins with vigilance.

Always scrutinize URLs, especially those that appear after a redirection.

If a CAPTCHA page presents unusual instructions beyond a simple tick-box, or asks you to press a series of keyboard commands, consider it a red flag.

For organizations, the incident underscores the urgent need for advanced malware protection featuring zero-hour defense capabilities, designed to detect sophisticated techniques like clipboard injections and real-time analysis of web page behavior, rather than simply scanning for known binaries.

ClickFix is more than just another malware variant; it’s a masterclass in psychological manipulation, a stark reminder that the most dangerous threats often wear the most familiar disguises.

As we navigate an increasingly complex digital world, our best defense remains an informed mind and an unwavering skepticism.

The digital arms race continues, and the battleground is increasingly shifting from our machines to our minds.

Author

  • LNGFRM Team

    Frank DiBernardo handles LNGFRM's Foodie and Miscellaneous writing tasks. He's always getting ideas from users, so don't be afraid to send an email to the editor.

Daily Newsletter
Subscribe to our Newletter!
You May Also Like

Mohit Bansal: On Zero-Headcount Security Scaling

Mohit Bansal’s approach to security engineering at Webflow rests on a deceptively simple reframe: treating fixed headcount not as a limitation to work around but as a firm design constraint that shapes every architectural decision, from how vulnerabilities get prioritized to how vendor risk gets automated away. His core discipline is pragmatic sequencing over theoretical perfection—getting 80 percent coverage on five critical risks rather than chasing 100 percent on two—paired with a relentless drive to automate repetitive data-gathering so a fixed team can spend its limited human judgment on the problems that actually require it.

By Mike Malone
Published June 30, 2026
© 2026 LNGFRM. All rights reserved.