Microsoft has warned users of its Windows operating system about a rising cyber threat that masquerades as a fake CAPTCHA test. This threat, part of a campaign called "ClickFix," tricks victims into following instructions that secretly run malicious commands on their computers. The threat actors use fake verification pages to deceive users into taking actions that appear to be routine security checks but ultimately lead to the execution of harmful commands.
The attack begins when a user visits a compromised website. Instead of the usual page, a fake verification or repair window appears, mimicking a standard security procedure. However, unlike legitimate CAPTCHA services, this fake test requires users to exit their browser entirely. The user is then instructed to copy a short text, open the "Run" dialog box in Windows, paste the text, and press Enter. This action, seemingly harmless, grants the attacker full control over the computer.
What makes this campaign particularly dangerous is its ability to evade both users and traditional antivirus software. The attackers use a two-step technique to bypass security measures. First, they secretly download a malicious script into the browser's cache, disguising it as a harmless image. Second, they use a short command that, when executed, searches the hard drive for the hidden file, renames it to a script file, and runs it in the background without displaying any pop-ups or error messages.
Once executed, the script penetrates the system deeply, using built-in administrative tools like PowerShell and Windows Management Instrumentation (WMI) to gather detailed information about the system and download additional malware. The malware then loads directly into the computer's memory, making it harder to detect. The ultimate goal of this operation is to steal sensitive data, including browser-stored passwords, personal credentials, and other data on the device.
To maintain long-term access, the malware modifies system settings, extracts hidden backdoors, and schedules automated tasks to continue operating silently in the background. Microsoft emphasizes that staying secure depends on a combination of smart protection measures and user vigilance. Built-in protection tools, such as Microsoft Defender SmartScreen and Defender for Endpoint, provide multi-layered defense by blocking known malicious websites and identifying suspicious behavior associated with the "ClickFix" technique.
Microsoft classifies these active threats under names like Trojan:Win32/TermFix. IT administrators are advised to enable cloud protection, web protection, network monitoring, and script logging to monitor unusual command activity. However, the first line of defense relies on users' awareness of the true nature of security checks. Legitimate services will never ask users to copy and paste commands into the "Run" box, Command Prompt, PowerShell, or Terminal.
Users are advised to treat any such requests as malicious attacks. By being cautious and informed, users can protect themselves from this growing cyber threat. Microsoft's alert serves as a reminder of the importance of cybersecurity awareness and the need for users to be vigilant when encountering unexpected security checks or requests for sensitive information.
Key points
- The "ClickFix" campaign uses fake CAPTCHA tests to trick users into executing malicious commands.
- The threat evades traditional antivirus software by using a two-step technique to bypass security measures.
- Users can protect themselves by being cautious of unexpected security checks and requests for sensitive information.