ClickFix Attacks Go Mainstream, Infecting PCs and Macs via Fake CAPTCHA Prompts
Ars Technica reports ClickFix attacks have become a mainstream malware technique, using compromised websites and fake CAPTCHA prompts to trick PC and Mac users into pasting terminal commands.
According to Ars Technica, the method works because visitors to compromised sites are presented with what appears to be a CAPTCHA challenge. Instead of solving a puzzle, they are instructed to paste and run a command. Enough visitors comply that the technique has become widespread. The report said the bar for launching the attack is low: a hacked website, a fake overlay and one command are sufficient.
Independent researcher Kevin Beaumont observed Thursday that Reddit is 'becoming post after post after post of people getting their computer infected via ClickFix.' He added that 'legit websites everywhere [are] getting hacked to serve the fake captcha prompts,' according to Ars Technica. The report said the technique is no longer limited to niche or experimental campaigns. It has been adopted by a broad range of malware pushers, and even hacking groups backed by the Kremlin have joined in.
The report also addressed how more seasoned internet users respond to the attacks. Many of them, including a fair number who read Ars Technica, quickly dismiss the threat, according to the article. They typically blame the people who fall for the scams and marvel at their gullibility and lack of attention.
Ars Technica reported that the reality is different for more casual users. For them, using computers and the internet has become so difficult that they have grown desensitized to instructions that seem ridiculous and burdensome. The article pointed to impossible-to-close interstitials, CAPTCHAs with an endless series of pictures to analyze, and constantly changing interfaces that bury the features they are looking for. Those conditions make it easier for a fake CAPTCHA that asks for a terminal command to blend into the noise.
The attack affects both PCs and Macs, according to Ars Technica. The report said the technique's spread is tied to its low cost and high yield. Attackers do not need a sophisticated exploit chain when they can persuade a visitor to run a command themselves. As Beaumont's observation suggested, the results are showing up in public posts from users who discover their machines have been infected.
Ars Technica's report framed ClickFix as a mainstream security problem rather than an isolated trick. It said the technique's requirements are minimal and its adoption is broad. The article did not provide a count of victims or a list of affected websites. It quoted Beaumont and described the conditions that make the attack effective.
Editor's Summary ClickFix attacks have become a mainstream method for infecting PCs and Macs by using compromised websites and fake CAPTCHA prompts to persuade users to paste and run terminal commands, Ars Technica reported. Independent researcher Kevin Beaumont said Reddit is filling with reports of infections and that legitimate websites are being hacked to serve the prompts. The technique's low barrier and broad adoption, including by Kremlin-backed hacking groups, have made it a widespread malware delivery method.