Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
initial-access-methoddefense-evasion-methodloader-delivery-mechanismcommand-and-control-method

Fake CAPTCHA (ClickFix) Social Engineering Used for Fileless Malware Delivery

Updated 3mo agoFirst seen Jan 27, 20265 sources

Security researchers reported an active malware distribution technique that abuses bogus CAPTCHA pages to trick users into executing attacker-supplied commands on Windows. In the ClearFake campaign analyzed by Expel, victims land on a compromised site and are instructed to press Win + R, then paste and run a clipboard-seeded command—an approach commonly referred to as ClickFix—which results in malicious PowerShell execution. The campaign emphasizes living-off-the-land tradecraft and evasion, including proxy execution by abusing the trusted Windows script C:\Windows\System32\SyncAppvPublishingServer.vbs to launch PowerShell in hidden mode and reduce the chance of AV detection.

Separate measurement and telemetry on the same broader tactic found large-scale infrastructure supporting fake CAPTCHA lures: a Censys analysis identified 9,494 breached websites hosting counterfeit verification pages, with ~70% appearing nearly identical. The most common infection mechanisms involved clipboard manipulation leading to VBScript and PowerShell execution (with significant counts of each observed), alongside other delivery paths such as MSIEXEC-based installation of malicious Windows Installer packages. Researchers also observed use of the Matrix push command-and-control framework to support fileless deployment, noting that these intrusions can leave no traditional executable artifacts and may evade signature-based detection.

Share:
Fake CAPTCHA (ClickFix) Social Engineering Used for Fileless Malware Delivery
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 27, 20265mo ago

Researchers disclose ClickFix variant abusing App-V and Google Calendar

Researchers reported a new ClickFix-style campaign that abuses the signed Microsoft App-V script SyncAppvPublishingServer.vbs instead of launching PowerShell directly. The attack used a public Google Calendar ICS file as a dead-drop resolver, then staged in-memory payloads that ultimately launched Amatera Stealer.

Expel details ClearFake's ClickFix and proxy-execution techniques

Expel researchers disclosed that ClearFake uses fake CAPTCHA prompts to trick users into pasting malicious PowerShell commands from the clipboard into the Windows Run dialog. They also described the campaign's use of the legitimate SyncAppvPublishingServer.vbs script for hidden proxy execution and estimated nearly 150,000 infections since August 2025.

Jan 26, 20265mo ago

Censys identifies thousands of breached sites hosting fake CAPTCHA lures

Censys analysis found 9,494 compromised websites serving bogus CAPTCHA pages used for malware distribution. Researchers observed several delivery chains, including clipboard-injected PowerShell and VBScript, MSIEXEC-based installers, and Matrix Push for fileless deployment.

Nov 18, 20257mo ago

Darktrace detects and blocks ClearFake activity on a customer device

On November 18, 2025, Darktrace observed likely ClearFake activity on a single device, including mshta.exe execution, Smart Chain-related requests, and attempts to retrieve payloads from suspicious infrastructure. Darktrace said its Autonomous Response blocked the outbound connections and likely prevented delivery of an information stealer.

Aug 1, 202511mo ago

ClearFake infections begin scaling via blockchain-backed delivery

Based on smart-contract transaction history, Expel assessed that the ClearFake campaign had been infecting systems since August 2025. The operation used EtherHiding on the Binance Smart Chain and other resilient hosting methods to support large-scale malware delivery.

Jun 1, 20233y ago

ClearFake campaign first identified using fake browser updates

ClearFake was first identified in mid-2023 as a malicious campaign using injected JavaScript on compromised websites, often WordPress sites, to trick users with fake browser update and CAPTCHA-style lures. Victims were commonly driven to these sites through SEO poisoning.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

42 LINKEDOpen in app
Affected products
7 linked
PowershellWordpressGithubGithubWindows InstallerWindowsCloudflare
Organizations
18 linked
BinanceMicrosoft CorporationKrollVirustotalDarktraceGitHubPacketLabsjsDelivrCensysExpelGoogleBlackpoint CyberHunt.ioCloudflareCyber Security NewsBitdefenderRescanaBinance Smart Chain
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.