
ClickFix Trick Spreads ACR Stealer via Paste-Run
Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…
Ukraine’s CERT says the Russia-linked Sandworm group is tricking targets into infecting their own PCs using compromised websites that display fake CAPTCHA checks. Victims are instructed to copy and paste a PowerShell command, which downloads malware and can lead to deeper compromise. CERT also warns Sandworm continues using messaging apps (including Signal) to socially engineer targets into installing bogus “security” software.
CERT-UA reports that Sandworm has shifted toward a ClickFix-style social engineering technique. Victims land on compromised, otherwise legitimate websites that display a fake CAPTCHA security check. Instead of clicking a box to verify they are human, users are instructed to copy and paste a PowerShell command into their Windows computer. Running that command downloads malware that can be used for persistence and further compromise. CERT-UA observed this technique across more than 10 compromised websites during June and July.
Sandworm also runs a parallel track on mobile devices. According to CERT-UA, the group distributes malware disguised as security applications through messaging apps rather than official app stores. Once installed, this malware can secretly collect contacts, files, device information and real-time location data.
The fake CAPTCHA lure works because it mimics a routine, low-friction action people perform constantly online. Pasting a command feels procedural rather than risky when framed as "verification." On the mobile side, Sandworm has reportedly used Signal to build rapport with military personnel and other targets over weeks before ever making an ask. That drawn-out trust-building, sometimes reinforced with cash payments, lowers a target's guard well before the request to run malicious files or install a bogus antivirus app arrives.
Organizations, especially in government and defense settings, should reinforce that legitimate CAPTCHAs never require running commands, and that IT-approved channels are the only source for security software. Staff should be encouraged to report suspicious website prompts and messaging app requests to run files or install apps, rather than acting on them directly. Recognizing the long-con pattern, where trust is cultivated over time before a malicious ask is made, and treating cash incentives tied to technical instructions as a red flag, can help reduce the chance that these techniques succeed against staff who use Windows endpoints and Android devices.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
CERT-UA found Sandworm compromising websites to show fake CAPTCHA checks that, instead of verifying a human, instruct users to copy and paste a PowerShell command into their Windows computer, which downloads malware.
CERT-UA observed this technique on more than 10 compromised websites during June and July.
Yes, CERT-UA reported that the group targets Android devices with malware disguised as security applications distributed through messaging apps, which can collect contacts, files, device information and location data.
CERT-UA said hackers often spend weeks building trust with military personnel and other targets over Signal before asking them to run malicious files, sometimes offering cash payments.
You land on a normal site, and suddenly a CAPTCHA pops up saying you must prove you’re human. But this one is different: it tells you to copy and paste a long PowerShell command into Windows. That’s Sandworm’s fake CAPTCHA trick to install malware from a compromised site. Here’s the aha: a real CAPTCHA never asks you to run commands. Same with Android, no legit security app arrives as a random Signal or chat link from someone offering to 'protect you' or even pay you. If any website or chat ever tells you to run a command or install security software, stop, take a screenshot and report it to IT or security immediately.

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…

Researchers reported a real phishing campaign (“Operation BlueDash”) that tricks users with a “secure document” lure and routes them to a fake Microsoft Store…

Threat actors are using fake CAPTCHA pages on compromised or lookalike websites to trick people into copying and pasting malicious commands (“paste and run”).…

ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…

A legal-sector threat intel report says adversary-in-the-middle (AiTM) phishing is now the most common way attackers gain initial access to law firms, because…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…