Lo Que Se Habla
🇪🇸🇬🇧
News, celebrities, tech and sport — Spain's daily essentials
ClickFix: the scam using fake CAPTCHA to hack your computer
Tech & AI inteligencia artificial 3 min read

ClickFix: the scam using fake CAPTCHA to hack your computer

A social engineering scam that began proliferating in late 2023 is gaining ground among cybercriminals: ClickFix, an attack that exploits fake CAPTCHAs to deceive you into executing malicious commands on your own computer. It requires no technical sophistication, just psychological manipulation. And it works.

How the fake CAPTCHA scam works

According to xataka.com, the mechanics are simple but effective. Attackers create a web page that mimics a technical error, a conventional CAPTCHA or an apparently legitimate security warning. It can reach you via phishing email, fraudulent ads or suspicious links on real websites.

Once inside that page, you receive instructions asking you to perform seemingly normal steps: solve an alleged CAPTCHA, verify your identity. But here comes the dangerous part: the website instructs you to open the terminal or Run window on your computer (Windows + R) and paste a code that supposedly will "unlock" the content.

Most disturbing is that some attacks copy the malicious code directly to your clipboard using JavaScript. You just have to press Windows + R and then Control + V. It's automatic, quick, and that's why it's dangerous.

What can happen after executing the command

The malicious code you execute can do practically anything, depending on the attacker's campaign. Credential theft, installation of remote access trojans, total system hijacking — the cybercriminal would have absolute control over your computer and could do whatever they wanted without you knowing.

It works on both Windows and macOS, which broadens the scope of the attack. The problem is that once you execute that command, the malware has already entered. After that, anything is possible.

Why the weak link is always human

ClickFix is a classic example of why cybersecurity depends more on the user than on any firewall. The attack page can copy the visual design of sites you see every day: the look of Google, Chrome, Windows or known CAPTCHA systems. The idea is for you to let your guard down because you believe you are somewhere you recognize.

Attackers take advantage of the fact that we are on autopilot. We solve CAPTCHAs without thinking. We read "technical error" and we act. We don't question the instructions because they appear to come from a trusted source.

How to protect yourself from ClickFix

The recommendations are clear-cut:

  • Distrust any website that asks you to open the terminal or Run window. This should be an immediate red flag. No legitimate site will ask you for this.
  • Read carefully before acting, even if the design is familiar. Verify that the URL is correct and that the instructions make sense.
  • Don't copy or paste commands without knowing what they do. If you don't understand what you're being asked to do, don't do it.
  • Be especially cautious with links that come to you via email, social media or ads.

The attack is simple to execute, but it's also simple to avoid if you keep your guard up. The question is: how many more users will fall for the scam as these attacks gain popularity?

Source: xataka.com

You may also like

Europe forces Apple to open clipboard; Microsoft wins another battle
Tech & AI

Europe forces Apple to open clipboard; Microsoft wins another battle

Apple has lost another regulatory battle in Europe as Microsoft succeeds in forcing the iPhone maker to create a shared clipboard solution between…

Google Pixel 11: massive leak exposes all specs and prices ahead of launch
Tech & AI

Google Pixel 11: massive leak exposes all specs and prices ahead of launch

A comprehensive leak has revealed technical specs, design and pricing of Google's Pixel 11 ahead of Wednesday's Made by Google event.

Alibaba launches AI that codes autonomously for 16 days non-stop
Tech & AI

Alibaba launches AI that codes autonomously for 16 days non-stop

Alibaba's Qwen 3.8-Max AI worked alone for 16 consecutive days writing and improving code without human intervention, accumulating hundreds of…