Lure theme
Fake CAPTCHA verification
The dominant ClickFix pretext. A page imitates a human-verification challenge, then replaces the puzzle with keyboard instructions presented as the way to complete the check. It works because verification is one of the few things on the web where being told to perform an odd little ritual is normal, so the instruction does not stand out.
- First reported
- 2024-09
- Targets
- Windows · macOS
- Campaigns on record
- 20
Approximate. CAPTCHA-styled pages appear in public reporting from around September 2024, roughly six months after the first ClickFix pages, which used an update pretext instead.
Also reported as FakeCAPTCHA · Fake human verification · I am not a robot lure · Verification challenge lure
What a victim sees
A narrow panel centred over a dimmed or empty page, styled as a bot check: a shield or robot glyph, a checkbox-shaped control, and progress wording about confirming you are human. Selecting the control produces no puzzle. The panel instead expands into a short numbered list — on Windows, hold the Windows key and press R, then paste, then press Enter; on macOS, open Terminal from Spotlight, paste, and press Return. A verification code or reference number is usually displayed alongside, which both explains what you are supposedly pasting and gives the page an air of record-keeping. Some builds add a spinner or a countdown so the panel appears to be working while you follow the steps.
Described rather than shown. This site publishes no screenshots of lure pages and reproduces none of their markup, because a working copy of a fake verification page is a fake verification page regardless of why it was made.
The tell-tale sign
A real CAPTCHA is solved inside the browser window. If verification asks you to press keys outside the browser — the Run dialog, Terminal, anything that takes a command — it is not verification.
The underlying rule is the same for every theme on this site, and it is the one worth remembering: no legitimate website will ever ask you to press Windows+R, to open Terminal, or to paste anything into either one. Why that rule holds.
Campaigns using this lure
StopAndProtect ClickFix operation
Status as last assessed: ActiveCheck Point Research published this analysis on 18 August 2026, naming the operation StopAndProtect after the ransomware family it first noticed in mid-May. The infrastructure is other people's websites: hacked WordPress installations — close to 2,000 named in the operators' own file lists — carry the lure, serve every stage, relay commands, and hold what is taken. A Windows visitor to one of them meets a counterfeit CAPTCHA that puts a PowerShell command on the clipboard. Two PowerShell stages and two .NET stages later comes a toolkit: a file encryptor, an SMB and USB worm, a screen locker, a VBS spreader, a stealer of files and credentials, and a chat window between operator and victim. Exposed directory listings let Check Point parse logs holding more than 6,000 unique IP addresses by late July, most in the US, Russia, and India, some of them sandboxes rather than victims.
ID f468583cFirst seen 2026-04-24Last seen 2026-07-24WindowsLatrodectus and Supper in Poland
Status as last assessed: ActiveCERT Polska assisted law enforcement after an intrusion at a large Polish organisation, and traced the way in to one user who obeyed a bogus human-verification page. The instruction was to paste a line into the Windows Run box; it fetched content with curl and piped it into PowerShell. The payload was a DLL side-loaded by a legitimate Intel executable in an %APPDATA% folder, unpacking to Latrodectus version 2.3 and tagged internally with the group name Kallichore; the analysts found no public account of the 2.x branch. Two further DLLs taken off the same workstation unpacked to Supper, a backdoor CERT Polska associates with the run-up to ransomware, persisting as a scheduled task named to resemble a Google updater. The report does not establish which stage put the Supper files on the machine, only that the intrusion began at the verification page.
ID 7bdefaadFirst seen —Last seen —WindowsInterlock ransomware and FileFix
Status as last assessed: ActiveInterlock has been run against businesses and critical infrastructure in North America and Europe since September 2024. Two ways in are on record: a drive-by download from broken-into websites, or a counterfeit CAPTCHA page whose numbered steps talked the visitor into pasting the clipboard into the Run box — later into a file-manager address bar, the variant called FileFix. Both routes started a PowerShell stage that pulled down a remote access trojan dressed as a browser update or a VPN client installer. The DFIR Report documented a PHP rewrite of that trojan in June 2025, reached through the KongTuke web-inject and calling home over tunnel hostnames. A joint FBI, CISA, HHS and MS-ISAC advisory followed eight days later. Operators then took credentials, moved between hosts over RDP, pushed data to cloud storage, and encrypted virtual machines.
ID 7d2eb0fdFirst seen 2024-09-01Last seen 2025-07-14WindowsLumma Stealer's PNG stego loader
Status as last assessed: ActiveHuntress traced incidents in which a counterfeit human-verification page, served from Cloudflare Pages subdomains, placed an mshta command on the visitor's clipboard and told them to run it from the Windows Run box. The page held its second-stage script XOR-encrypted in a variable and injected it through a blob URL, which frustrates string matching. mshta retrieved a JScript file from a bare IP address written with a hex-encoded second octet; that ran PowerShell in memory, which decrypted a .NET assembly and loaded it reflectively. The assembly carried an AES-encrypted PNG in its manifest resources and rebuilt Donut-packed shellcode out of the red channel of the pixels, XORing each value against 114. Injection into explorer.exe followed, and the unpacked payload was Lumma Stealer. Huntress released a refreshed configuration extractor for the samples it recovered.
ID eb151a21First seen 2025-10-01Last seen 2025-11-24WindowsARECHCLIENT2 via GHOSTPULSE
Status as last assessed: ActiveElastic Security Labs traced a Windows infection chain that opens with a page imitating Cloudflare's anti-bot check. The page reports each visitor's address to an attacker-run host, then places a shortened-link fetch on the clipboard for the victim to paste into the Run dialog. What arrives is an archive holding a benign decoy executable beside a rogue DLL, so the GHOSTPULSE loader starts by sideloading. One encrypted file alongside carries both the loader's configuration and its own second stage; a separate image file, tagged IDAT, holds the payload for later. A further .NET loader neuters AMSI, decrypts its cargo with a key lifted from a PE section, and starts ARECHCLIENT2 — also known as SectopRAT — in memory. The two lure domains sat on an advertising agency's compromised server, and a banner-hash pivot from the hardcoded C2 addresses mapped further live nodes.
ID ce70ba83First seen 2024-12-13Last seen 2025-06-15WindowsXFiles Stealer via early IClickFix
Status as last assessed: ArchivedAn earlier build of the same WordPress-injection cluster, examined by Sekoia.io in February 2025, carried a different payload chain. Around 160 sites bore the marker tag at that point, nothing filtered incoming traffic, and one script fetched through a Short.gy shortlink held the lure, the clipboard code and the command together. The counterfeit Cloudflare page of that period spelled out keyboard steps instead of presenting a challenge a visitor would already recognise, which Sekoia judges the weaker of the two designs. Anyone who complied downloaded an MSI installer, a build of Emmenhtal Loader, which then retrieved XFiles Stealer. Sekoia assigned this activity to the IClickFix cluster only in retrospect, after working through the framework's later NetSupport RAT stage at the end of 2025.
ID 61ac3fa9First seen 2024-12-18Last seen 2025-02-01WindowsNetSupport RAT via IClickFix
Status as last assessed: ActiveSekoia.io's TDR team traced a JavaScript framework it calls IClickFix, planted in more than 3,800 breached WordPress sites across 82 countries. The injected tag pulls a script from a registered domain, and that request passes through a filter built on the YOURLS open-source shortener, which screens out scanners before forwarding selected visitors. Two further scripts follow, the second parked on a separate hacked site, after which the page is swapped for a counterfeit Cloudflare Turnstile check. A visitor who works through the on-screen steps pastes a concealed instruction into the Run box, fetching a PowerShell stage served with a .json extension. That stage unpacks fifteen files beneath ProgramData, adds a Run key and starts a NetSupport RAT client reporting to registered gateway domains. Sekoia dates the cluster to December 2024 and judges it capable of thousands of infections daily.
ID 5d17aaf3First seen 2024-12-18Last seen 2025-12-18WindowsAsyncRAT and XWorm on one host
Status as last assessed: ActivePivoting through VirusTotal relationships from the fake-verification infrastructure, Trend Micro found a single host serving files that submissions had labelled as two different remote-access tools: AsyncRAT and XWorm. The delivery path ended in a video extension, matching the media-file naming used throughout the rest of the report. The same address had been reused over time to serve remote-access trojans and small downloaders, which the researchers read as one modular loader picking a payload to suit whatever machine it lands on. No specific lure page is tied to this host in the report; the connection is an infrastructure one, drawn from submission history and graph relationships rather than from an investigated incident.
ID 4d857e92First seen —Last seen 2025-05-19Windowsmshta lures fetching remote HTAs
Status as last assessed: ActiveAlongside the audio-file cases, Trend Micro's incident data held a run of counterfeit verification pages whose common trait was simply the instruction to paste a line into a system prompt. Each page assembled that line in the browser, decoded it from base64 and placed it on the clipboard, so the visitor never read the destination. Most aimed mshta at a remote HTML Application on a short-lived domain; one used a hidden PowerShell instruction that retrieved a text file and evaluated its contents. Victims arrived through malvertising, through email, and in one investigated case through a poisoned search result for a stately-home visitor attraction, where the top-ranked link was a legitimate website that had been broken into. Trend Micro does not tie these particular hosts to any named malware family.
ID c0b21902First seen —Last seen 2025-05-19WindowsHotel lost-property phishing mail
Status as last assessed: ActiveA phishing run aimed at hotels and other accommodation businesses used subject lines about property a departing guest had supposedly forgotten: passports, laptops, medical kit, an unlocked safe deposit box. The wording is formal and time-pressured. Some messages carried a link, others attached a PDF whose embedded link did the same work. Either way the recipient passed through an open redirector on an unrelated and well-regarded website before arriving at a page imitating a human-verification check, which placed a command on the clipboard and asked them to run it. Trend Micro names seven domains behind this lure, most of them rearrangements of the words guest, reserve, item and found. Endpoint telemetry in the report shows the chain in practice, with a mail client opening a browser at one of those domains.
ID 0bd90ac4First seen —Last seen 2025-05-19WindowsEmmenhtal Loader inside an MP3
Status as last assessed: ActiveTrend Micro's managed detection team traced a delivery chain that opens with a counterfeit human-verification page. The visitor is told to paste an mshta command, which fetches what looks like an ordinary audio track. The track really does play music, but it also carries JavaScript wrapped first in base64 and then in hexadecimal, which Trend Micro attributes to the Emmenhtal loader. Unwrapping it starts a hidden PowerShell process that pulls down a second script disguised with a spreadsheet extension, injects code into svchost.exe and reaches a command server on port 8587. Lumma Stealer follows, together with DLL sideloading from a browser-updater executable dropped into a user profile directory, and a browser launched on a throwaway profile against a local listener. Several of the audio files were sourced from a royalty-free music library and modified.
ID deeaf6a4First seen —Last seen 2025-05-19WindowsDeerStealer via an IUAM kit page
Status as last assessed: ActiveA Windows-only deployment of the kit. The operator left platform detection switched off, so visitors on any other system were offered nothing at all. Ticking the checkbox on the counterfeit human-verification widget ran background JavaScript that loaded a PowerShell one-liner into the clipboard, while a panel told the reader to open the Run dialog, paste and press Enter. Doing so fetched a batch file into the temporary folder and ran it immediately; the batch file then pulled down an MSI installer carrying the DeerStealer information stealer. Unit 42 lists eight sample hashes and fifteen host names for this strand, with no role given for the hosts and no dates. The article separately warns that some pages of this sort sat on ordinary websites the operator had broken into, so a share of those hosts may belong to victims.
ID d9e3bd3cFirst seen —Last seen —WindowsUAC-0050 overlap in Ukrainian mail
Status as last assessed: ActiveA Ukrainian-language mailing dated 31 October 2024, written as though passing on paperwork or details the recipient had asked for. Each message carried a compressed HTML attachment; opening it produced a local page running the public fake-CAPTCHA lure. Pasting what the page supplied started a second script, which called on the Windows background transfer service to fetch and launch the payload. Proofpoint suspects that payload was Lucky Volunteer, an information stealer it has seen only rarely and last recorded in early 2023, dropped then by AresLoader in a TA579 operation. One oddity: the page stayed in English while the message body and the attachment names were Ukrainian. Proofpoint places the activity as overlapping with UAC-0050. Three addresses are published — two fetch URLs and one control endpoint.
ID 468c485bFirst seen 2024-10-31Last seen 2024-10-31WindowsXWorm via ChatGPT malvertising
Status as last assessed: ActiveSeen from the middle of October 2024, with indicators dated the 19th. Outbrain recommendation panels on a large technology site carried a teaser promising more from ChatGPT; following it led to a site presenting itself as a prompt-writing service. The page ran a restyled build of the same public fake-CAPTCHA kit, this time framed as an invitation to join a community, with the clipboard trick sitting behind it. Running what had been copied invoked mshta against an obfuscated HTA file, which reached out for two further scripts: one loaded XWorm by way of RegAsm and started its hidden-desktop plugin, the other planted a registry autorun so the first came back at every boot. Proofpoint noted Russian comments in the site's script that a language model had probably written.
ID fcb64726First seen 2024-10-19Last seen 2024-10-19WindowsRicardo marketplace lure in German
Status as last assessed: ActiveA German-language mailing aimed at organisations in Switzerland, with indicators dated 25 September 2024. The messages posed as Ricardo, a marketplace familiar to Swiss consumers, and carried links to a landing page built from the public fake-CAPTCHA kit. The page told the reader to click, copy and paste in order to clear a supposed problem; behind that, script code pulled a ZIP archive from a Dropbox share, then a clipboard routine handed PowerShell the job of unpacking it and starting the batch file inside. Proofpoint was not able to recover the final malware at the time, but inferred from the control traffic that AsyncRAT or PureLog Stealer was the likely end of the chain. Published indicators cover the landing-page URL on an .es host, the Dropbox download link, one control address and two file hashes.
ID bd2a1de1First seen 2024-09-25Last seen 2024-09-25WindowsLumma Stealer via GitHub issue mail
Status as last assessed: ActiveProofpoint dated this activity to 18 September 2024. The operators abused GitHub's own mail: by opening an issue or leaving a comment on a repository they caused GitHub to notify everyone subscribed to it, carrying the attacker's wording inside a message that genuinely originated at the platform. The wording posed as a security alert and pointed readers at github-scanner[.]com, a counterfeit of the site. That page ran an off-the-shelf fake-CAPTCHA kit and padded the clipboard so the victim would not spot the real instruction once it sat in the Run box. Executing it fetched a binary and ended in Lumma Stealer. Around 300 organisations worldwide showed up as affected in Proofpoint's own telemetry. Seven .shop control domains and one Steam profile page are published alongside two payload hashes.
ID c28a85bbFirst seen 2024-09-18Last seen 2024-09-18WindowsAMOS via a fake Spectrum page
Status as last assessed: ActiveReported publicly in June 2025 by CloudSEK and dated by Microsoft to the closing days of May, this operation pointed Mac owners at delivery pages made up to look like Spectrum, the American cable, broadband and telephone company. The page showed a counterfeit CAPTCHA with an alternate verification button; the steps it then displayed were written for Windows even when the reader was on a Mac, while the command placed on the clipboard differed by platform. On macOS that command asks for the account password again and again until one checks out against directory services, keeps it in the temporary folder, pulls a file down from applemacios[.]com, uses the captured password to strip the quarantine flag, marks the file runnable and starts it. The file belongs to the Atomic Stealer family, whose Poseidon and Odyssey variants take browser cookies, saved passwords and cryptocurrency wallet material.
ID 1f22b447First seen 2025-05-30Last seen 2025-06-06macOS · WindowsOBSCURE#BAT via a Discord lure
Status as last assessed: ActiveOBSCURE#BAT is the name Securonix gave to activity that installs an altered build of r77, an open-source rootkit whose value to an operator is staying hidden and staying put. Microsoft attributes one of the lure pages it pulls apart in this write-up to that same cluster. The page presents itself as a Discord server that wants a visitor identified before letting them join, and borrows the platform's own logo to sell the idea. Its script waits for the verify button and then uses the browser's clipboard interface to load a command, with no hidden frame and no message from another document involved — plainer than the other example Microsoft dissects, where a concealed frame signals the parent page. Recorded alongside it are a landing page, a batch file on a public file host, and two addresses used for control between February and March 2025.
ID 092c751dFirst seen 2025-02-24Last seen 2025-03-27WindowsScreenConnect via a fake SSA site
Status as last assessed: ActiveA run observed in June 2025 posed as the United States Social Security Administration to plant ScreenConnect, a commercial remote support product, on the reader's machine. Mail came from a real Brazilian domain that had been broken into, and the footer carried genuine links to the agency's social accounts; the body claimed something was wrong with the recipient's benefits statement. Its button pointed at a Google advertising redirect rather than the destination, so hovering over the link — the habit awareness training teaches — showed nothing useful. Following it produced access-ssa-gov[.]es, a look-alike registered under Spain's country domain, which copied the agency's front page behind a blur. A counterfeit verification pop-up then walked the reader through steps ending in a PowerShell script that fetched and started the remote access tool, handing the operator the device.
ID 64b61ec1First seen 2025-06-02Last seen 2025-06-02WindowsMintsLoader from Storm-0426
Status as last assessed: ActiveIn March 2025 Microsoft watched the group it tracks as Storm-0426 send thousands of messages to recipients in Germany. The pretext was a bill from a web hosting company, and the link went not to the lure but to a Prometheus traffic direction system standing on a spread of broken-into sites. Visitors who passed through it landed on mein-lonos-cloude[.]de, a name that plays on a German hosting brand and which Microsoft states the attacker controlled. There the ClickFix routine asked for a human verification step; carrying out the displayed steps ran the operator's code. The goal was MintsLoader, a loader whose purpose is to bring down further malware once it has a foothold. Microsoft records derko-meru[.]online as the loader's controller. Both names were observed on 26 March 2025.
ID daec320fFirst seen 2025-03-26Last seen 2025-03-26Windows