{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:20:56.238Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"ClickFix fake-CAPTCHA social engineering floods the threat landscape","date":"2025","date_precision":"year","victim_org":"Multiple organisations and consumers (technique)","sector":"Other","country":"Multiple","primary_vector":"Watering Hole / Malvertising","secondary_vectors":["Tech Support Scam","Spear Phishing (Email)"],"ai_involvement":"Unknown","ai_notes":"Some ClickFix lure pages and follow-on infrastructure have been reported as AI-assisted in their construction, but Proofpoint's reporting does not confirm AI involvement in the technique itself.","outcomes":["Credential Theft","Ransomware Deployment","Data Breach"],"loss_usd":null,"loss_note":"No aggregate loss figure; this entry documents a technique adopted across many criminal and state-linked actors rather than a single victim.","records_affected":null,"threat_actor":"Multiple, including cybercriminal and state-aligned groups tracked by Proofpoint","summary":"Proofpoint documented ClickFix as a social engineering technique that became pervasive from 2024 into 2025: web pages, fake CAPTCHA gates, fake browser or document error dialogs and phishing emails instruct the user to copy a supplied string, open the Windows Run dialog or a terminal, and execute it. The technique has been adopted by financially motivated criminals and state-aligned actors alike to deliver infostealers, loaders and remote access tools.","how_it_worked":"The victim reaches a page, often through malvertising, a compromised site, a search result or an emailed link, that presents a plausible obstacle: 'verify you are human', 'this document failed to load, run the fix', or a fake Chrome update error. Instructions walk the user through pressing Windows+R, pressing Ctrl+V and pressing Enter. The clipboard has already been populated by JavaScript with a PowerShell or mshta command, frequently padded with whitespace so the malicious portion is scrolled out of view in the Run box. Executing it downloads and runs the payload under the user's own privileges, sidestepping email attachment scanning, macro blocking and download reputation checks entirely because the user is the delivery mechanism.","lessons":"Disable or monitor the Run dialog through policy, alert on clipboard-sourced script execution, and train staff on the single unambiguous rule that no legitimate website ever asks you to paste a command into your operating system.","confidence":"Confirmed","sources":[{"title":"Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape","url":"https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape","publisher":"Proofpoint"},{"title":"Deceptive CAPTCHA: ClickFix Campaign Uses Clipboard Injection to Deliver Malware","url":"https://securityonline.info/deceptive-captcha-clickfix-campaign-uses-clipboard-injection-to-deliver-malware/","publisher":"SecurityOnline"},{"title":"Inside ClickFix: How Fake Prompts Took Over the Web","url":"https://netlas.io/blog/fake_prompts/","publisher":"Netlas"}],"entry_type":"campaign","slug":"2025-clickfix-fake-captcha-social-engineering-floods-the-threat-landscape","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-clickfix-fake-captcha-social-engineering-floods-the-threat-landscape"}]}