That “Prove You’re Human” Box May Be Trying to Steal Your Data

by | Apr 5, 2026 | Cybersecurity, Internet, Phishing and Other Scams, Security

Home  ›  Blog  ›  Current Post

If you have spent any time on the internet lately, you have seen a CAPTCHA. The little box that says "I'm not a robot." Maybe some blurry traffic lights to click on. You know the drill.

Attackers know it too. And now they are using your familiarity with that process to put malware on your computer without ever exploiting a single piece of software.

The attack is called ClickFix. It is one of the fastest-growing threats in cybersecurity right now, and it is targeting regular users at companies just like yours.

What ClickFix Is and How It Works

ClickFix is a widespread campaign that uses fraudulent CAPTCHA pages to socially engineer victims into executing malicious scripts themselves.

Here is the basic sequence:

  1. You land on a compromised website. It could be a page you reached through a phishing email, an ad, or even a legitimate site that was hacked without the owner knowing.
  2. A pop-up appears that looks like a standard Cloudflare or Google verification prompt.
  3. Instead of just clicking a box, the page instructs you to press Windows Key + R, then Ctrl + V, then Enter.
  4. You follow the steps because they look like a routine system action.
  5. Your computer is now infected.

The reason those three keystrokes work is straightforward. Malicious JavaScript embedded in the site loads a fake CAPTCHA page that closely mimics Cloudflare's verification interface. A malicious PowerShell command is already placed on the clipboard and executes when pasted into the Run dialog, giving the attacker code execution without triggering browser download prompts or security warnings.

You did not click a suspicious link. You did not open a strange attachment. You ran the attack yourself because the page told you it was just a verification step.

What Happens After You Run It

StealC, one common payload delivered this way, exfiltrates browser credentials, cryptocurrency wallets, Outlook credentials, system information, and screenshots to an attacker-controlled server.

Other campaigns deliver different payloads. Attackers can deploy tools such as LummaStealer, a highly evasive infostealer designed to harvest credentials, financial information, and other sensitive data at scale.

In more serious incidents, the payload is a remote access trojan. That gives the attacker persistent access to the machine, not just a one-time data grab. From there they can move laterally through your network, deploy ransomware, or sell access to other criminal groups.

Stealers, remote access trojans, and loaders appear within minutes of execution, often before anyone suspects something is wrong, leaving little time for containment.

The Numbers Are Not Reassuring

This is not a niche threat. The scale of ClickFix adoption by attackers has been dramatic.

517%
surge in attacks,
H1 2025 (ESET)
#1
initial access method
per Microsoft 2025
47%
of all attacks tracked
by Microsoft Defender
  • ClickFix attacks surged 517% in the first half of 2025, becoming the second most common attack vector behind only phishing and accounting for nearly 8% of all blocked attacks in that period.
  • Microsoft's 2025 Digital Defense Report named ClickFix the number one initial access method, responsible for 47% of all attacks observed by Microsoft Defender Experts, surpassing traditional phishing at 35%.
  • Between May 2024 and May 2025, the volume of phishing URLs tied to ClickFix nearly quadrupled.
  • In early 2025, Microsoft observed thousands of devices being affected per month, even with endpoint detection and response solutions enabled.

That last point matters. This attack is slipping past tools that were supposed to catch it.

Why Security Tools Often Miss It

Traditional security is built to catch unauthorized activity. ClickFix generates authorized activity.

Email gateways are not involved and malware scanners may have nothing to inspect. Endpoint tools can record the event, but the command itself is executed by the user through a trusted shell.

When the victim pastes the command, the system treats it as a normal action. Many endpoint detection and response tools interpret it the same way.

The attack is also designed to evade blocklists. ClickFix campaigns often contain only a clean URL that redirects through traffic distribution systems before landing on the attack page. Browser protections like Google Safe Browsing do not trigger because the browser is not downloading an executable. The user is.

Real Organizations Are Getting Hit

This is not just an individual user problem.

The website of iClicker, a popular student engagement platform used by approximately 5,000 instructors and 7 million students, was compromised with a ClickFix attack between April 12 and April 16, 2025. Visitors who clicked the "I'm not a robot" button had a PowerShell script silently copied to their Windows clipboard, then were instructed to run it.

More than 100 automotive industry websites were infected via a streaming service provider in an attack reported in March 2025 targeting car dealerships. Healthcare has been targeted as well, with malicious code injected into a physical therapy video site that redirected users to ClickFix prompts.

According to the U.S. Department of Health and Human Services, ClickFix has extensive reach and has appeared in many services used by the general public.

What ClickFix Looks Like in 2026

The technique is still evolving. Attackers are not standing still.

In January 2026, a new ClickFix variant called CrashFix was identified, delivered through a malicious Chrome extension that impersonated a legitimate ad blocker. The attack deliberately crashed the victim's browser, then prompted them to follow recovery steps that executed the malicious command.

Recent campaigns have targeted social media content creators by claiming they are eligible for free verified badges, instructing them to copy authentication tokens from their browser cookies into a fake form. One campaign used 115 web pages across its attack chain and eight separate data exfiltration endpoints.

Malvertising is another common delivery path. In one campaign, users who pressed play on a free movie streaming site had a ClickFix landing page open in a new tab, funneling tens of thousands of unique visitors to scam pages in a single day.

The One Rule That Stops This Attack

Remember This

No real CAPTCHA, no real verification system, and no real browser check will ever ask you to open PowerShell or the Windows Run dialog, paste text into it, and press Enter.

Full stop. If a website asks you to do that, close the tab.

Quick Test

Not sure if your clipboard was hijacked? Open Notepad and press Ctrl + V. If it contains a command with words like "powershell," "cmd," "IEX," or a URL you do not recognize, that page was attempting to infect you. Close your browser and contact your IT provider immediately.

What Businesses in the Dayton Area Should Do

User awareness is the first line of defense here, but it cannot be the only one.

  • Train your staff on this specific attack. General phishing awareness is not enough. Your employees need to know that no legitimate website will ask them to run commands on their own computer. Show them what the prompt looks like. Make it concrete.
  • Restrict PowerShell for standard users. Most employees do not need to run PowerShell scripts as part of their normal work. Locking down access to it is one of the most effective technical controls available.
  • Use endpoint protection with behavioral detection. Standard antivirus is not enough. You need a solution that monitors for unusual process behavior, not just known malware signatures. Bitdefender GravityZone with EDR is what we deploy for managed clients at Dayton Allied Business Solutions for exactly this reason.
  • Keep software and browsers updated. Attackers target outdated environments. Patch management removes the low-hanging fruit.
  • Have a plan for when something gets through. Know who to call. Know what steps come first. Incident response without a plan costs you more time and more money than having one.

The Bottom Line

ClickFix works because it exploits trust in everyday computer interactions. It does not need a vulnerability in your software. It needs a user who follows instructions.

ClickFix campaigns impersonate infrastructure: browsers, operating systems, update mechanisms, verification flows, and error states. Social engineering training often focuses on teaching users to question unexpected emails. Users are far less likely to question instructions that appear to come from the system itself.

That is exactly what makes this one dangerous.

Is your business protected?

We can assess your current security posture and help you put the right controls in place.

Sources: Microsoft Security Blog, ESET H1 2025 Threat Report, Infosecurity Magazine, U.S. Department of Health and Human Services HC3, Splunk Security Research, TechRepublic, BeyondMachines, The Hacker News, ChannelE2E

Filed under: All Posts

About the Author

David Pfiffner is the owner of Dayton Allied Business Solutions, a managed IT and web solutions company serving businesses in the Huber Heights and Dayton, Ohio area. Nearly two decades of hands-on technology experience.

Need IT Help?

Proactive IT management, cybersecurity, backup, and web solutions for Dayton businesses. Flat monthly pricing. Local support.

Explore the Blog

Browse all posts for practical technology tips, IT advice, and web strategy for small businesses in the Dayton area.

Ready to Put This Into Practice?

If something in this post resonated, let’s talk. We work with small businesses in the Dayton area on exactly these kinds of problems.

Special Offer!

Get a free 30-minute review of your IT setup. We look at what you have, tell you what is at risk, and give you one thing you can do today at no cost and no obligation.

Grab the Offer!