PGH Networks

ClickFix Fake CAPTCHAs Are Tricking Office Users Into Self-Infecting

September 24, 2026· PGH Networks Team· 5 min readBusiness & Tech Insights
ClickFix Fake CAPTCHAs Are Tricking Office Users Into Self-Infecting

What happened

A new global threat report from CTM360, covered this week via feeds.feedburner.com, analyzed roughly 17,000 URLs tied to a social-engineering technique known as ClickFix. According to the reporting, ClickFix has become the most common way attackers gain initial access to enterprise networks, and it does it without an exploit, without an email attachment, and without dropping a file on disk. The lure is a fake verification prompt, often a counterfeit CAPTCHA or "fix this error" dialog, that instructs the visitor to copy a command and run it themselves.

The report traces the technique from a novelty in late 2023 into a subscription-style criminal product with on-chain infrastructure and state-sponsored users, and argues that blocking malicious domains is no longer a meaningful defense on its own, because the pages are frequently hosted on otherwise trusted, legitimate websites. We have not independently verified the dataset, and the article summary does not break out victim counts by industry or region, so treat specific numbers as the researchers' findings rather than ours.

people sitting on chair in front of computer

Why this matters for Pittsburgh small and mid-sized businesses

The reason ClickFix works so well against a 40-person CPA firm or a 120-person manufacturer is that it targets the one control you cannot patch: a busy person who wants the page to load. The victim gets a prompt that looks like the same verification screen they clear a dozen times a week, follows three steps, and pastes a command into the Windows Run box or a terminal. From the endpoint's perspective, an authorized user just launched a legitimate script host. There is no malicious attachment for your mail filter to quarantine and, in many cases, nothing written to disk for signature-based tools to scan.

Map that to the work our clients actually do. A paralegal researching a case lands on a compromised industry site. A controller during tax season clicks through a vendor portal that has been quietly altered. A plant supervisor searching for a firmware download hits a page that tells them to "repair" their browser. In each case the follow-on payload is usually credential theft or a session-token grab, and stolen Microsoft 365 tokens are the shortest path we see to business email compromise, fraudulent wire instructions, and mailbox rules that quietly forward client correspondence offsite.

The compliance consequences land differently by vertical, and that is worth thinking through before an incident, not after. For medical and dental practices, an attacker inside a mailbox is a potential HIPAA breach determination with a 60-day notification clock. For registered advisors and lenders, the FTC Safeguards Rule expects documented incident response and monitoring, not best intentions. For defense suppliers in the Mon Valley and along the airport corridor, a credential-theft event touching CUI is both a DFARS reporting question and an awkward conversation about whether your CMMC Level 2 awareness and incident-response practices were actually operating. SOC 2 auditors will ask the same thing in different words.

One more local wrinkle: ClickFix also shows up wrapped in AI-tool bait, fake "AI assistant" installers and browser add-ons. If your staff are experimenting with AI tools faster than your policies are keeping up, that is an exposure worth closing with a real acceptable-use policy.

What to do about it this week

  1. Send a plain-language warning to every employee today. The message is one sentence: no legitimate website, CAPTCHA, or error page will ever ask you to copy and paste a command, press Windows+R, or open PowerShell. If a page asks, close the tab and tell IT. Repeat it in your next all-hands.
  2. Ask your IT provider to confirm script-host controls are enforced. Specifically, verify current policy for PowerShell (constrained language mode or execution policy plus logging), mshta, and clipboard-driven Run-box execution, and confirm your EDR or MDR tooling is alerting on command-line launches from a browser process. If nobody can show you the policy, that is the finding.
  3. Verify script-block and process-creation logging is on and retained. Command-line auditing is what turns "we think something happened" into a defensible timeline for your auditor or cyber insurer. Confirm the retention period in writing.
  4. Harden identity so a stolen credential is not a stolen company. Phishing-resistant MFA where you can get it, conditional access by device compliance, token-lifetime review, and alerting on new mailbox forwarding rules. These controls blunt ClickFix payloads even when the click already happened.
  5. Run a simulated awareness exercise aimed at this specific lure. Most SMB training libraries still lean on attachment phishing. Ask whether yours includes a fake-verification scenario, and if not, request it.
  6. Publish an approved software and AI tool list. Give people a sanctioned way to get what they need so they stop hunting for installers. If AI adoption is driving the demand, an AI readiness assessment and a short acceptable-use policy will do more good than another blocked category.
  7. Rehearse the 30-minute response. Who isolates the endpoint, who revokes sessions and resets credentials, who decides whether a regulator or prime contractor needs notice. Walk it once with your vCIO so the first real event is not the rehearsal.

man in blue dress shirt sitting on rolling chair inside room with monitors

How we help

PGH Networks builds this kind of layered defense for Pittsburgh-area firms every day: managed IT with hardened endpoint policy and patch management, monitored detection and response, Microsoft 365 identity hardening, targeted user awareness training, and compliance mapping for HIPAA, SOC 2, FTC Safeguards, and CMMC. If you are not certain whether a ClickFix-style paste-and-run attack would be caught on your network tonight, let us take a look.

Talk to us

Call 724.888.7007 or reach out through the contact form to schedule a short review of your endpoint, identity, and awareness controls.

Share

Related reading

Call usBook a meeting