Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligencecredential-access-methodloader-delivery-mechanismdefense-evasion-method

Fake CAPTCHA/ClickFix Social Engineering Used to Deliver Malware and Steal Sessions

Updated 3mo agoFirst seen Jan 23, 20263 sources

Threat actors are increasingly using fake CAPTCHA / verification pages as a scalable social-engineering lure to deliver malware and steal credentials by abusing users’ trust in routine web security checks. Research highlighted a large, fragmented ecosystem of lookalike fake CAPTCHA pages hosted across ~9,494 compromised sites and malicious properties, where roughly 70% of observed pages share near-identical visuals while delivering dozens of distinct payload variants via different execution models, including clipboard-driven instructions that lead victims to run PowerShell or VBScript downloaders.

Separately, a ClickFix campaign targeting Facebook users—especially content creators and businesses seeking verification—uses fake “verification” portals to trick victims into manually extracting and submitting browser session tokens (notably c_user and xs) via developer tools, enabling account takeover without exploiting software vulnerabilities. In parallel, the ClearFake campaign (a malicious JavaScript framework injected into hacked websites) has adopted ClickFix-style fake CAPTCHA lures and added more evasive “living off the land” behavior, including proxy execution to run PowerShell through trusted Windows features and shifting distribution to a popular CDN, reducing the effectiveness of defenses that rely primarily on blocking known-bad domains/IPs.

Share:
Fake CAPTCHA/ClickFix Social Engineering Used to Deliver Malware and Steal Sessions
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 23, 20265mo ago

Censys identifies large fake CAPTCHA ecosystem across 9,494 sites

Censys analysts reported a broad fake verification ecosystem spanning about 9,494 compromised websites and malicious properties, with roughly 70% sharing nearly identical fake CAPTCHA pages. They identified at least 32 payload variants, including clipboard-driven PowerShell or VBScript execution, MSI delivery via msiexec, and fileless push-notification abuse through Matrix Push C2.

Jan 22, 20265mo ago

Cyber Security News reports ClickFix Facebook hijacking campaign

Cyber Security News reported on the widespread ClickFix campaign stealing Facebook accounts through fake verification pages and manual session-token theft. The coverage highlighted urgency tactics, instructional videos, and the instruction for victims not to log out for 24 hours so stolen cookies remain valid.

Jan 20, 20265mo ago

Expel documents ClearFake's updated fake-CAPTCHA delivery chain

Expel published technical details on ClearFake's large-scale campaign, describing compromised websites that inject fake CAPTCHA prompts and use ClickFix-style clipboard lures to make users run malware. The report also noted anti-analysis checks, smart-contract-based payload retrieval, and a UUID tracking mechanism to avoid reinfection and record infections.

ClearFake adopts more evasive LOTL proxy execution techniques

The ClearFake fake-CAPTCHA malware campaign recently shifted to a more evasive execution chain that abuses SyncAppvPublishingServer.vbs to launch hidden PowerShell through command injection. It also moved payload hosting to the legitimate jsDelivr CDN while continuing to retrieve JavaScript stages from BNB Smart Chain testnet smart contracts.

Jan 1, 20251y ago

ClickFix campaign expands with resilient token-theft infrastructure

From early 2025, the Facebook-focused ClickFix operation grew significantly and adopted distributed hosting and collection services such as Netlify, Vercel, Wasmer, GitHub Pages, Surge, Formspark, and submit-form.com. The workflow validated stolen c_user and xs tokens in real time and escalated to collecting recovery codes or passwords when token reuse failed.

ClickFix Facebook session hijacking campaign begins

A social-engineering campaign later dubbed ClickFix began operating in January 2025, targeting Facebook content creators, monetized pages, and businesses. The attackers used fake Facebook verification and account-review pages to trick victims into extracting and submitting their own session cookies.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Malware
1 linked
Affected products
4 linked
Windows InstallerFacebookWindowsVercel
Organizations
14 linked
CensysCloudflareWasmerPalo Alto NetworksHunt.ioMeta PlatformsExpelGitHubVercelNetlifyjsDelivrSurgeFormsparksubmit-form.com
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.