Microsoft warns fake CAPTCHA tests are hijacking Windows PCs

Microsoft has issued a cautionary note to Windows users regarding a rising cyber threat that cleverly disguises itself as a benign CAPTCHA test. Cybercriminals are employing fraudulent verification pages to deceive unsuspecting individuals into executing commands that can unleash malicious software on their systems. This alarming trend transforms what should be a routine security measure into a perilous pitfall, with the sophistication of these attacks making them increasingly difficult to detect.

<span id="Howthetrap_unfolds”>How the trap unfolds

In our daily online experiences, encountering a CAPTCHA—those brief tests prompting users to check a box or identify images—has become almost instinctive. However, the perpetrators behind the newly uncovered “ClickFix” campaign are exploiting this familiarity. The deception begins when a user stumbles upon a compromised website. Instead of a typical webpage, a counterfeit verification or repair window appears, masquerading as a standard security check. Unlike legitimate CAPTCHA services that securely process user actions within the browser, this malicious ruse prompts users to step outside their browser environment.

The prompt instructs the victim to copy a snippet of text, open the Windows Run dialog box (by pressing Windows Key + R), paste the copied content, and hit Enter. To the average user, this may seem like a simple system fix or a routine identity verification. However, it effectively hands over control of the computer to the attacker.

<span id="Howitbypassesyourantivirus_software”>How it bypasses your antivirus software

This campaign’s danger lies in its ability to deceive both users and conventional antivirus software. Typically, security tools monitor for suspicious file downloads, but the ClickFix technique cleverly circumvents this safeguard through a two-step approach:

  1. Pre-loading the trap: Before any interaction with the fake CAPTCHA, the compromised site covertly downloads a hefty malicious script into the browser’s temporary storage (cache). To disguise its true nature, the file is camouflaged as a harmless image (.PNG).
  2. Short and silent commands: Since the malicious payload is already nestled in the browser’s cache, the command pasted into the Run box does not require any new downloads. Instead, it executes a quick search on the hard drive, locates the concealed “image” file, renames it to a script (.vbs), and launches it in the background—all without any pop-ups or error messages.

This brevity in the pasted command allows attackers to bypass character limits in Windows while evading detection from traditional download scanners.

<span id="Whathappensbehindthescenes”>What happens behind the scenes

Once activated, the script delves deeper into the compromised system. It employs built-in administrative tools such as PowerShell and Windows Management Instrumentation (WMI) to collect detailed system information and retrieve additional malicious files. This initiates a multi-stage infection process:

  • Memory infiltration: The malware loads harmful scripts directly into the computer’s temporary memory, avoiding hard drive storage and making detection even more challenging.
  • Data theft: The ultimate aim of this covert operation is to target and pilfer stored web browser passwords, personal credentials, and sensitive device data.
  • Long-term control: To ensure continued access even after a system reboot, the malware discreetly alters system settings, extracts hidden background tools, and schedules automated tasks to persistently operate in the background.

<span id="Howtostay_protected”>How to stay protected

Microsoft underscores that safeguarding oneself hinges on a blend of robust security software and user awareness. Built-in protections such as Microsoft Defender SmartScreen, Defender for Office 365, and Defender for Endpoint provide a layered defense, blocking known malicious sites and flagging suspicious “ClickFix” activities. Security systems categorize these threats under designations like Trojan:Win32/ClickFix and Trojan:Win32/TermFix. IT administrators are encouraged to enable cloud-delivered protection, web protection, network monitoring, and script-logging to identify abnormal command activity.

However, the foremost line of defense is understanding what constitutes a legitimate security test.

<span id="Thegoldenruleofweb_safety”>The golden rule of web safety

No authentic CAPTCHA, browser verification service, or official IT support team will ever request that you copy and paste commands into your Windows Run dialog, Command Prompt, PowerShell, or Terminal. Any such request should be immediately regarded as a potential malicious attack.

Source:
gbhackers

Winsage
Microsoft warns fake CAPTCHA tests are hijacking Windows PCs