Analytics Story: Fake CAPTCHA Campaigns

Description

This analytic story addresses the emerging threat of Fake CAPTCHA and ClickFix campaigns that exploit users' familiarity with verification systems to deliver malware through clipboard manipulation techniques. First observed in early 2024 and increasing through 2025, these campaigns use deceptive interfaces that mimic legitimate CAPTCHA systems to trick users into executing malicious commands.

Why it matters

Fake CAPTCHA campaigns represent a sophisticated evolution in social engineering attacks that rely entirely on manipulating user behavior rather than exploiting technical vulnerabilities. These attacks begin with victims landing on malicious websites through phishing emails, malvertising, or compromised legitimate sites. The site presents what appears to be a standard CAPTCHA verification interface with familiar branding from Google reCAPTCHA or Cloudflare. When users interact with the fake CAPTCHA, malicious JavaScript silently copies commands to their clipboard. Users are then instructed to perform additional verification steps such as pressing Windows+R followed by Ctrl+V, unknowingly pasting and executing malicious commands. These commands typically download and run additional malware using PowerShell scripts that operate in hidden windows. Common payloads include information stealers (Lumma, Redline, Vidar, PureLog), Remote Access Trojans (NetSupport, XWorm, AsyncRAT, Quasar), and multi-stage payloads that can deploy multiple malware families from a single infection.

Detections

Name ▲▼ Technique ▲▼ Type ▲▼
Windows RunMRU Command Execution Indirect Command Execution Anomaly
Windows Content Copied from Browser was Executed PowerShell, Windows Command Shell, Indirect Command Execution TTP
Windows Finger.exe Connecting to a Remote Host Application Layer Protocol TTP
Windows For Loop Usage Within Cmd.exe To Execute Commands Windows Command Shell Anomaly
LOLBAS Network Connection On Uncommon Port Ingress Tool Transfer, System Binary Proxy Execution, Exfiltration Over Web Service Anomaly
LOLBAS With Network Traffic Ingress Tool Transfer, System Binary Proxy Execution, Exfiltration Over Web Service TTP
Windows PowerShell FakeCAPTCHA Clipboard Execution PowerShell, Windows Command Shell, Malicious Link TTP
Windows Process Accessing IronLanguages Repository On GitHub Command and Scripting Interpreter, Ingress Tool Transfer Anomaly
Windows Node.exe Executing JS Script In Immediate Folder JavaScript TTP
LOLBAS Rare Network Connection Ingress Tool Transfer, System Binary Proxy Execution, Exfiltration Over Web Service Anomaly

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼
Sysmon EventID 13 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 24 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
CrowdStrike ProcessRollup2 Other crowdstrike:events:sensor crowdstrike
Windows Event Log Security 4688 Windows icon Windows XmlWinEventLog XmlWinEventLog:Security
Sysmon EventID 1 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Sysmon EventID 3 Windows icon Windows XmlWinEventLog XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
Cisco Network Visibility Module Flow Data Network icon Network cisco:nvm:flowdata:v2 not_applicable

References


Source: GitHub | Version: 2