Detection Alert: #ClickFix #FakeCaptcha | Sigma Rule

Listen to this Post

⚠️ #Phishing Just Got More Dangerous! Hackers are using FAKE CAPTCHA pop-ups to infect systems! This sneaky phishing attack tricks users into running malware through Windows Run commands—leading to credential theft, RAT infections, and full system compromise. This method is being used to distribute Lumma Stealer, AsyncRAT, NetSupport RAT, and more.

How This Attack Works (Sigma Rule Detection)

1️⃣ Phishing email or malicious website delivers the trap.
2️⃣ A fake “I am not a robot” CAPTCHA appears.
3️⃣ Clicking injects a hidden malicious command into your clipboard.
4️⃣ You’re told to press Windows + R and execute the clipboard content.
5️⃣ This abuses LOLBins (mshta.exe, powershell.exe) to execute remote malware!

Why This is Dangerous?

🚫 Not a typical phishing attack.

🚫 Directly executes remotely hosted malicious files in memory without dropping payloads.

How to Stay Safe?

✅ NEVER execute clipboard commands blindly.

✅ Restrict script execution from the Run dialog.

✅ Report & block suspicious sites ASAP.

You Should Know:

Detecting & Mitigating Fake CAPTCHA Attacks