Fake CAPTCHA Campaigns Use Windows Run Prompts to Deliver Malware to PCs

ClickFix attacks use fake CAPTCHA or repair prompts to persuade users to open Windows Run, paste an attacker-provided command and execute it, turning a routine-looking interaction into malware delivery. In a campaign identified by Microsoft, compromised websites preload a disguised script in the browser cache; the command retrieves and runs it, helping the attack evade security tools focused on suspicious downloads and files. The technique exposes a gap in endpoint defenses that expect a malicious artifact to arrive first, leaving detection to later stages—where, as security analysts warn, timing is critical. A separate campaign used attacker-created ChatGPT Custom GPTs to steer victims to ClickFix pages and a malicious installer that ultimately deployed a remote-access trojan; Huntress reported at least 40 infections. Users should treat any webpage that asks them to run a command on their computer as suspicious: legitimate CAPTCHA checks stay within the browser.
In the Microsoft-described campaign, the command searches browser-profile cache locations, including Firefox’s, for a file matching an attacker-set size, copies the cached content into a temporary VBScript file and runs it with Windows Script Host; the command suppresses output and errors to make the activity less visible.
The ChatGPT lure began with sponsored Google search results for queries such as “chatgpt.” One attacker-created Custom GPT, named “Plus 5.6,” claimed service was limited on its primary domain and urged users to use a backup Google Sites link instead.
In the Custom GPT campaign, the downloaded MSI installer launched a DLL-sideloading chain that loaded shellcode and then a persistence script and remote-access trojan, according to Huntress.
Publishers
14
Articles
4
Reach
18