📌 Inside ClickFix: how fake prompts took over the web
Fake CAPTCHAs and “verification” pages coax users into pasting system commands via trusted tools like Run or PowerShell. No exploit, no download — the victim executes the payload themselves, sidestepping many defenses.
What’s inside
1️⃣ The evolution: from simple error popups to polished reCAPTCHA/Turnstile clones, OS-aware pages, and video walk-throughs that raise urgency.
2️⃣ Scale of the problem: ESET tracked a 517% rise (H2’24→H1’25); ClickFix-style lures now account for ~8% of blocked attacks.
3️⃣ APT adoption: ClearFake, TA571, Lazarus, Kimsuky, Callisto/Sednit, MuddyWater, APT36 — cross-platform, high-impact use.
4️⃣ Anatomy of an attack: delivery → deceptive prompt → clipboard injection → user-initiated execution → payload retrieval.
5️⃣ Real-world sample: a faux CAPTCHA plants a VBS downloader command, then runs the fetched script from %TEMP%.
6️⃣ Why it lands: Microsoft’s 2025 report calls ClickFix the top initial-access vector, tied to 47% of recorded intrusions.
Bonus: the article includes hunting tips and how to stop these chains at scale. 🔎🛡️
👉 Read here: https://netlas.io/blog/fake_prompts/
Post #534
816