216.73.217.22

Caught in the CAPTCHA: How ClickFix is Weaponizing Verification Fatigue to Deliver RATs & Infostealers

· Published 22/05/2025 21:54 · Modified 23/05/2025 13:07

Export JSON

Essential information

Published
22/05/2025 21:54
Modified
23/05/2025 13:07
Tags
2025-05-22 captcha clipboard injection infostealer lumma netsupport rat powershell rat sectoprat social engineering
Related entities
10 observables, 1 intrusion sets (apt), 3 techniques (mitre), 3 malware

Description

Threat actors are exploiting user fatigue with anti-spam mechanisms through a technique called ClickFix. This method involves compromising websites and embedding fraudulent images, which, when solved by unsuspecting users, lead to the execution of malicious code. The attack chain typically includes commands and the use of legitimate Windows tools to download and execute additional payloads. Common malware delivered through this technique includes Stealer, , and . The success of ClickFix relies heavily on and user interaction, making user education and awareness crucial in mitigating these attacks. Recommendations include training users to recognize suspicious requests, restricting execution, and deploying advanced EDR solutions.

External references