How it works and how to avoid this scam to hack your computer

Let’s explain to you what is the fake CAPTCHA scamalso called as ClickFix. This is a type of social engineering attack that appeared at the end of 2023, and that is gradually becoming popular, becoming a danger for Internet users.

The idea of ​​the scam is simple, use something that we have all automated such as completing a CAPTCHA to convince the user to execute malicious commands on your own computer. We are going to explain how this scam works so that you can identify it, and then we will give you several tips to avoid it.

What is the fake CAPTCHA scam?

The fake CAPTCHA scam, also known as ClickFix, is a social engineering attack. This means that the attackers are not trying to scam you in a technical way, but rather by manipulating you so that you yourself are the one who opens the door for them through deception.

Specifically, the ClickFix technique consists of tricking the user into executing a malicious command on their computer, and affects both Windows and macOS. They do this by taking advantage of their victims’ tendency to solve small technical problems and other seemingly harmless interactions, such as human verification and CAPTCHAs.

The way ClickFix works is simple. Use a website as a hook that shows you a scenario technical error, false CAPTCHA or security notices apparently legitimate. You can be taken to these websites with phishing techniques, both by email and by fraudulent links or ads on legitimate pages.

On this website where you are shown an error or a false CAPTCHA, you are given instructions to continue. These instructions guide you through manual steps, such as open a run or terminal screen and paste a code or command.

One of the complex things is that, sometimes, on the website where ClickFix is ​​made, the malicious code is copied directly to your clipboard using JavaScript. So, the instructions can be as simple as pressing Windows + R and then Control + V, opening the Windows launch window by directly pasting the code.

This is malicious code can do many thingsit all depends on the attack campaign in which it is used. It can be used to steal credentials, but also to install remote access Trojans with which the cybercriminal can do whatever they want on your computer.

This may seem like a seemingly easy attack to detect, but in the end it follows the rules of social engineering: the weakest link in the chain of online security is always the human.

To carry out the manipulation, the page where you are given the instructions may have recognizable visual aspectslike that of some conventional CAPTCHA website, classic error messages from Chrome, Windows or Mac, or whatever. The idea is to manipulate you, make you believe that you are in an environment that you know so that you let your guard down.

How to protect yourself against this attack

If you want to avoid this attack and not have it affect you, it is best to distrust any website that asks you to open the terminal or the window Execute from your computer. Don’t press Windows + R, this is immediately an alarm that it wants you to do something you shouldn’t on your computer.

It is also very important pay close attention to the pages that ask you to do thingseven if they look like pages you see every day, seemingly normal CAPTCHA systems, or error messages you think you’ve seen. Read the instructions for what is asked of you, try not to act automatically.

These are two tips that most experienced users know by heart. But here, you must remember that perhaps you or I are not the objective victims of these attacks, but rather many other not so experienced users who browse carelessly and without knowing how some Internet systems work.

The ClickFix attack is becoming popular with fake CAPTCHAs, so it is also worth remembering that these verification systems usually ask you to select images of a certain type or solve musical acuity challenges. But they will never ask you to execute commands on the computer or do things outside the browser. Therefore, whenever they ask you for something like this you should automatically distrust.

In Xataka Basics | What is PhishingAlert and how to use it to avoid identity theft scams at online casinos

Leave your vote

Leave a Comment

GIPHY App Key not set. Please check settings

Log In

Forgot password?

Forgot password?

Enter your account data and we will send you a link to reset your password.

Your password reset link appears to be invalid or expired.

Log in

Privacy Policy

Add to Collection

No Collections

Here you'll find all collections you've created before.