BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ClickFix Attacks Surge 517% in 2025, Fake CAPTCHAs Spread Malware

ClickFix and FileFix Phishing Attacks Surge: 517% Rise in Fake CAPTCHA and File Explorer Techniques Targeting Global Users

  • ClickFix attacks using fake CAPTCHA verifications have risen by 517% in early 2025, according to ESET.
  • The ClickFix technique leads to a range of threats, including info-stealing Malware, Ransomware, and custom nation-state malware.
  • Attack volumes are highest in Japan, Peru, Poland, Spain, and Slovakia.
  • A new method called FileFix uses Windows File Explorer to trick users into executing malicious code from their clipboard.
  • Recent phishing campaigns use multiple methods, including fake .gov domains and SharePoint links, to steal credentials and personal information.

Cybersecurity researchers from ESET have reported a substantial increase in cyberattacks using the ClickFix scheme, which uses deceptive CAPTCHA checks to gain initial system access. The attack method, which spreads via fake error messages, tricks victims into copying and running harmful commands, mainly targeting systems in Japan, Peru, Poland, Spain, and Slovakia.

- Advertisement -

Recent data shows a 517% increase in ClickFix incidents between late 2024 and early 2025. Attackers use ClickFix tactics to deliver various cyber threats, including infostealers, ransomware, and sophisticated malware. “The list of threats that ClickFix attacks lead to is growing by the day, including infostealers, ransomware, remote access trojans, cryptominers, post-exploitation tools, and even custom malware from nation-state-aligned threat actors,” said Jiří Kropáč, Director of Threat Prevention Labs at ESET.

The ClickFix mechanic works by displaying convincing CAPTCHA or error prompts, which ask users to copy scripts into the Windows Run dialog or macOS Terminal. These scripts then execute malicious code on the victim’s device. ESET noted that attackers are now selling tools that allow others to create their own ClickFix-based phishing pages, spreading the method further.

Security researcher mrd0x recently demonstrated a similar attack technique called FileFix. Instead of a CAPTCHA prompt, FileFix asks users to copy and paste a file path into Windows File Explorer. The clipboard contents actually contain a hidden PowerShell command that runs when pasted, giving attackers another method to execute code remotely. The FileFix approach combines Windows’ ability to execute code from the File Explorer address bar with social engineering tactics.

Alongside these developments, security teams have discovered new phishing campaigns that exploit trusted services and platforms. Some use fake .gov domains to lure victims, while others use aging web domains or distribute malicious ZIP files containing shortcut files that activate remote access tools like Remcos RAT.

- Advertisement -

Attackers have also used SharePoint-themed emails to send users to phishing pages hosted on genuine SharePoint domains, making detection more difficult. Experts note that these phishing links are hard to spot and widely trusted by users, which increases their effectiveness.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Nears $64K Despite Iran Tensions, Trader Caution

Bitcoin regained the $64,000 level despite renewed geopolitical tensions involving the US, Iran, and...

Micron’s AI HBM Boom: $435 to $1,750 Price Target Split

Wall Street's 2026 price targets for Micron stock show extreme divergence, ranging from around...

AI Chatbots May Reinforce Delusions in Vulnerable Users

Researchers propose a new "amplification spiral" framework to explain how AI chatbots could reinforce...

Bitcoin Plunges 50%, Sparking Fears of Imminent Market Collapse

Bitcoin's price has fallen to half its October 2025 peak, sparking fears of a...

Dash Eyes Philippines for Crypto Payments Expansion

Dash is exploring the Philippines as a target market for its low-cost crypto payment...

Must Read

What Is Binance Earn?

As someone who is passionate about cryptocurrency, I am always on the lookout for new opportunities to grow my portfolio. That's why I was...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading