Microsoft observed a ClickFix campaign where compromised websites show a fake CAPTCHA that tricks people into opening Windows Run and executing a pasted command. The attack hides a VBScript payload in the browser cache (disguised as an image) so the device already has the file locally when the victim runs the command, helping the malware evade simple download-based detection and bypass Run character limits.
How the Attack Worked
This campaign used a ClickFix-style fake verification step to trick visitors on compromised websites. Instead of a normal CAPTCHA check, a pop-up instructed users to open Windows Run, paste clipboard contents, and press Enter. That single action triggered a command that searched cached browser files for a VBScript payload disguised as an image, matched it by file size, copied it as a .vbs file, and executed it with wscript.exe.
Once running, the VBScript collected host details through WMI, fetched and ran a PowerShell script with execution policy bypassed, and later injected code into timeout.exe. Persistence was set up through a scheduled task that ran a Python payload via pythonw.exe after unpacking Python with tar.exe. Microsoft Defender Antivirus detects this behavior as Trojan:Win32/ClickFix and Trojan:Win32/TermFix.
Why It Succeeded
The attack succeeded by exploiting a gap between what users expect from web verification and what it actually asked them to do. People are used to clicking checkboxes or solving puzzles for CAPTCHAs, not opening system dialogs and running commands. Hiding the payload in the browser cache beforehand meant the malicious file was already present locally when the command ran, helping it slip past detection methods that focus on downloads and also getting around length limits in the Run dialog.
What to Watch For
- A CAPTCHA or verification prompt that asks you to open Windows Run or a terminal
- Instructions to paste clipboard contents and press Enter to "verify" you are human
- Any step that pushes you from a web page into an operating system action rather than a normal browser interaction
As Microsoft noted, a CAPTCHA should not ask users to run code. That single red flag is often enough to stop the chain before it starts.
Building Resistance
Organizations should train all employees, not just IT staff, to recognize ClickFix-style pretexts as a known malware delivery method. Because this technique relies on a single user action rather than a complex exploit, awareness at the point of the fake prompt is a critical control.
For security operations and endpoint administrators, detection should not rely solely on download alerts. Monitoring browser activity alongside unusual WScript, PowerShell, and scheduled-task activity, as well as reviewing the RunMRU registry key, can help catch this technique even when the payload itself avoids traditional download-based detection.
Key findings
- Compromised websites led visitors to a ClickFix-style fake verification step (fake CAPTCHA).
- Victims were instructed to open Windows Run and execute a command pasted from the clipboard.
- The VBScript payload was pre-fetched into the browser cache and disguised as an image so it was already on disk when executed.
- The command searched cached files (names starting with "f_") and matched the payload by file size, then copied it as a .vbs file and executed it with wscript.exe.
- The VBScript collected host details via WMI, fetched and ran a PowerShell script with execution policy bypassed, and later injected code into timeout.exe.
- Persistence was established using a scheduled task that ran a Python payload via pythonw.exe after unpacking Python with tar.exe.
- Microsoft Defender detects this behavior as Trojan:Win32/ClickFix and Trojan:Win32/TermFix.
- Microsoft advised hunters to look beyond downloads to browser activity, WScript/PowerShell/scheduled task events, and the RunMRU registry key.
Who’s being targeted
- Commonly targeted roles: All Employees, IT Helpdesk, Security Operations (SOC), Endpoint/IT Administrators.
- Affected industries: General / cross-industry (any web-browsing Windows users).
- Attack channels: website.
- Impersonated: CAPTCHA / website verification prompt.
Red flags to watch for
- A CAPTCHA should not ask you to run commands on your computer
- Instructions to use Windows Run and execute clipboard contents is highly unusual
- The step bypasses normal web verification flows and pushes OS-level actions
Frequently asked questions
What is a ClickFix attack?
ClickFix is a social engineering technique that gets victims to run attacker-supplied commands under the guise of a verification step, such as a fake CAPTCHA.
How does the fake CAPTCHA infect a computer?
The fake CAPTCHA pop-up tells users to open Windows Run, paste clipboard contents, and press Enter, which executes a command that locates a VBScript payload already cached in the browser disguised as an image.
Why is hiding the payload in browser cache significant?
Because the file is already on disk before the victim runs the command, the attack can evade simple download-based detection and bypass character limits in the Run dialog.
What should defenders monitor for this kind of attack?
Microsoft advised looking beyond download events to browser activity, unusual WScript, PowerShell, and scheduled-task activity, as well as the RunMRU registry key.
Read the video transcript
You solve a CAPTCHA, and then it says: "Open Windows Run, paste from your clipboard, press Enter." That is ClickFix. Behind that fake CAPTCHA, the site already stashed a VBScript in your browser cache, disguised as an image. The Run command just hunts for that hidden file and launches it with wscript.exe. Once it runs, it pulls PowerShell with execution policy bypassed, injects into timeout.exe, and drops a scheduled task that later runs a Python payload in the background. Microsoft flags this as Trojan:Win32/ClickFix and TermFix. A CAPTCHA should never tell you to open Run or paste commands. If any site does that, stop immediately and report it to Security, do not press Enter.