TWO recent investigations show ClickFix attacks concealing malicious payloads until after victims have followed instructions to paste and run a command. The social-engineering technique typically uses a fake technical problem or verification prompt—such as a CAPTCHA—to persuade people to execute code in Windows Run, PowerShell or macOS Terminal.
Flare researcher Assaf Morag reported a campaign delivering CrocoRat, a remote access Trojan and cryptocurrency stealer. A fake reCAPTCHA page tells visitors to open PowerShell and paste text. Rather than carrying the next payload directly, the command queries an attacker-controlled DNS TXT record for further instructions, which then start the download chain.
Flare also found an unexecuted Python launcher suggesting the malware could be tailored to the victim: a Flare spokesperson said corporate-looking systems may receive persistent remote access, while personal-looking systems may receive the RAT and credential and cryptocurrency stealers. Researchers do not know how victims were directed to the page.
Separately, Microsoft Threat Intelligence described a campaign using compromised websites to pre-fetch a script into the browser cache, disguised as a PNG, before prompting users to run a clipboard command. The cached script is then ready to execute, helping hide the payload and bypass the Windows Run dialog’s character limit. Microsoft said Defender protects against elements of the chain.
Flare recommends reducing the chance that copied commands are executed; the article also cites user training, alerts on clipboard-to-Run activity, PowerShell script-block logging and application controls as possible measures. The reports describe campaigns and techniques, not confirmed infection numbers.