Cybercriminals are increasingly exploiting fake CAPTCHA verifications through a social engineering technique called ClickFix, with attacks rising by 517% between the first and second half of 2024, according to ESET research.
## What is ClickFix?
ClickFix is a deceptive attack method that uses bogus error messages or fake CAPTCHA verification checks to trick victims into copying and pasting malicious scripts into Windows Run dialog or Apple macOS Terminal applications. Once executed, these scripts can deploy various threats including infostealers, ransomware, remote access trojans, cryptominers, and even nation-state malware.
“The list of threats that ClickFix attacks lead to is growing by the day,” said Jiří Kropáč, Director of Threat Prevention Labs at ESET. The attack’s popularity has led to cybercriminals advertising builders that help other attackers create ClickFix-weaponized landing pages.
## Geographic Impact
ESET data shows the highest concentration of ClickFix detections in Japan, Peru, Poland, Spain, and Slovakia, indicating the global reach of these campaigns.
## Evolution to FileFix
Security researcher mrd0x has demonstrated a new variant called FileFix, which tricks users into copying file paths into Windows File Explorer instead of using fake CAPTCHAs. This technique exploits File Explorer’s ability to execute commands through the address bar combined with web browser file upload features.
In FileFix attacks, victims see a message claiming a document has been shared with them, prompting them to copy a “file path” that actually contains hidden PowerShell commands. The malicious command is disguised using spaces and comment symbols to appear as a legitimate file path.
## Current Phishing Campaign Trends
Recent phishing campaigns demonstrate increasingly sophisticated tactics:
– **Government impersonation**: Using .gov domains to send fake unpaid toll notices
– **Strategic domain aging**: Employing long-lived domains to host fake CAPTCHA pages leading to spoofed Microsoft Teams sites
– **Multi-stage attacks**: Distributing malicious ZIP files containing Windows shortcut files that deploy Remcos RAT
– **Storage warnings**: Fake mailbox full alerts leading to credential theft pages hosted on IPFS
– **Legitimate platform abuse**: Using Vercel to host fake LogMeIn distribution sites
– **SMS campaigns**: Impersonating state DMVs to harvest personal and financial information
– **SharePoint exploitation**: Using Microsoft SharePoint domains to host credential harvesting pages
## Why SharePoint Attacks Are Effective
CyberProof researchers note that SharePoint-themed attacks are particularly successful because:
– Emails with SharePoint links are less likely to be flagged by security software
– Users trust Microsoft links and are less suspicious
– Phishing pages hosted on SharePoint are often dynamic and time-limited, making them harder for automated security tools to detect
## Key Takeaway
The rapid evolution from ClickFix to FileFix and the surge in sophisticated phishing campaigns highlight the need for enhanced user awareness and robust security measures. Organizations must stay vigilant against these evolving social engineering tactics that exploit user trust and legitimate platforms.
