TGViewer
Netlas.io Netlas.io @netlas · 2.32K subscribers
Post #534 816
📌 Inside ClickFix: how fake prompts took over the web

Fake CAPTCHAs and “verification” pages coax users into pasting system commands via trusted tools like Run or PowerShell. No exploit, no download — the victim executes the payload themselves, sidestepping many defenses.

What’s inside
1️⃣ The evolution: from simple error popups to polished reCAPTCHA/Turnstile clones, OS-aware pages, and video walk-throughs that raise urgency.
2️⃣ Scale of the problem: ESET tracked a 517% rise (H2’24→H1’25); ClickFix-style lures now account for ~8% of blocked attacks.
3️⃣ APT adoption: ClearFake, TA571, Lazarus, Kimsuky, Callisto/Sednit, MuddyWater, APT36 — cross-platform, high-impact use.
4️⃣ Anatomy of an attack: delivery → deceptive prompt → clipboard injection → user-initiated execution → payload retrieval.
5️⃣ Real-world sample: a faux CAPTCHA plants a VBS downloader command, then runs the fetched script from %TEMP%.
6️⃣ Why it lands: Microsoft’s 2025 report calls ClickFix the top initial-access vector, tied to 47% of recorded intrusions.

Bonus: the article includes hunting tips and how to stop these chains at scale. 🔎🛡️

👉 Read here: https://netlas.io/blog/fake_prompts/
netlas.io Inside ClickFix: How Fake Prompts Took Over the Web - Netlas Blog ClickFix turns fake CAPTCHAs into user-executed malware chains. Learn how campaigns evolve, how to hunt them at scale with Netlas, and how to stop them
  • 🔥 5
  • ❤ 3
  • 👾 3
  • 👍 2
More from @netlas
  1. Sep 23, 2026CVE-2026-87902: Path Traversal in WordPress leading to RCE, 9.2 Rating 🔥 Another newly di…
  2. Sep 22, 2026CVE-2026-93952: Improper Input Validation in VeloCloud Orchestrator, 10.0 Rating 🔥 A rece…
  3. Sep 21, 2026CVE-2026-13684 and others: Multiple vulnerabilities in Synology DSM, up to 9.8 Rating 🔥 S…
  4. Sep 18, 202611 new vulnerabilities in WordPress, no CVE assigned yet ❗️ WordPress 7.1.1 security relea…
  5. Sep 17, 2026CVE-2026-20329 and others: Multiple vulnerabilities in Cisco ASA, up to 9.9 Rating 🔥 Cisc…
  6. Sep 16, 2026CVE-2026-61642: Request smuggling is possible in Squid proxy, 7.7 Rating 🔥 A recently dis…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →