ClickFix

Fake-CAPTCHA Initial Access — Detection, Prevention, and the Download-Folder Evolution

517%
increase in ClickFix activity into 2025
>90%
delivery sites are compromised WordPress
~80%
of payloads are infostealers
3
keypresses to compromise via Win+X
3,500+
confirmed cases in ClickFix Hunter
Incident in progress? The response steps are on ClickFix Response. This page is how you get ready.
ClickFix exploits a trained behavior, not ignorance. We spent a decade training users to solve CAPTCHAs to prove they are human. ClickFix inverts that: a fake CAPTCHA tells the user to press Win+R, paste a “verification code,” and hit Enter. The “code” is a PowerShell stager. The payload is already in the clipboard before the user sees anything. This is not a phishing link — there is no suspicious URL to click. It is social engineering against a reflex.

How ClickFix Works

Understanding the full attack chain is prerequisite to both detection and prevention. ClickFix has two distinct delivery modes and a rapidly evolving payload delivery infrastructure.

Attack Chain

  1. User lands on a page. Either via a phishing email (targeted) or organic Google search to a compromised site (mass). The page loads a fake CAPTCHA — visually indistinguishable from Cloudflare Turnstile or hCaptcha. More than 90% of ClickFix delivery sites are legitimate WordPress sites compromised through vulnerable plugins, not attacker-owned infrastructure.
  2. User clicks the CAPTCHA button. JavaScript calls a token-gated API server which returns a payload unique to this visitor. The payload is placed in the user’s clipboard. What the user sees is benign: “I am not a robot — verification code: 8Xk29qm”. The actual clipboard content is a full PowerShell stager prepended to that string — only the visible tail is the decoy.
  3. User executes the command.
    • Win+R method: page instructs user to press Win+R, Ctrl+V, Enter. The run dialog launches the pasted command. Process tree: explorer.exe → cmd.exe / powershell.exe. Three keypresses to compromise.
    • Win+X method (now ~90% of cases): page instructs user to press Win+X, then I (opens Windows PowerShell / Terminal). Process tree: Windows Terminal → powershell.exe → [payload]. One extra step but more convincing UI, harder to detect.
  4. Stager runs. The first-stage PowerShell calls back to the same or a related host to retrieve a second-stage payload. LOLBins dominate stage 2: PowerShell, CMD, MSHTA, and curl are the most common loaders. The stager often runs inside a PowerShell runspace specifically to reduce EDR visibility.
  5. Payload delivered. ~80% infostealers (Vidar, Rhadamanthys, Amadey — often multiple simultaneously), ~15% loaders and RATs, ~5% ransomware. Infostealer deployment is a shotgun: a single dropper will attempt to install three or four separate families, dumping everything into the same folder on disk.

Payload-as-a-Service Architecture

Modern ClickFix campaigns operate a token-gated API backend. Every visitor who clicks the CAPTCHA button receives a uniquely obfuscated payload — 100 consecutive downloads from the same API return 100 distinct blobs (triple-dash encoding, base64, XOR variants) that all deobfuscate to the same final stage. The token rotates per-request, making bulk defensive sampling difficult. This is why YARA and IOC matching on command-line content no longer works: the string you observed yesterday will not appear again.

New Variant: Download-Folder Staging

Emerging technique (observed June 2026): The page click now silently downloads a file to %USERPROFILE%\Downloads\. The pasted command is benign — it only executes the already-downloaded file. The PowerShell command itself is clean. Standard command-line detection will not fire.

Detection: correlate file creation in the Downloads folder with a PowerShell entry appearing in the RunMRU registry key within a short time window. Password-protected zip delivery is a likely next step.

Payload Delivery Evolution

ClickFix evolves fast. Detections built against early variants are now largely obsolete. Each stage below was retired by attacker response to defensive coverage.
Era Technique Detection status
Early 2024 Raw command line, writes files to disk via Win+R Well-detected — PowerShell -WindowHidden / -bypass flags caught by most EDRs
Mid 2024 Light obfuscation + anti-forensics (RunMRU clearing) Detectable — EDRs deobfuscate; RunMRU wipe is a tell
Late 2024 Encoded command lines, still writes to disk Partially detected — EDRs decode; encoded blob is flaggable
Late 2025 Encrypted payloads + Win+R; per-visitor unique obfuscation IOC/YARA obsolete — unique blobs defeat signature matching
2025–current Win+X (~90% of cases) — opens Windows Terminal, hides in terminal process tree Harder to detect — Win+R rules don’t fire; requires terminal process chain detection
June 2026+ Download-folder staging — file pre-downloaded, command only executes local path New gap — command itself is clean; requires Downloads + RunMRU correlation
Key implication: Detections built in 2024 against Win+R LOLBin patterns or HTTP call signatures are now obsolete for the majority of campaigns. All payloads are per-visitor-unique and heavily obfuscated. YARA on clipboard content or command-line strings will not catch current ClickFix. Behavioral and process-chain detection is the only viable path.
1 Containment — Reduce the Execution Surface Now
Before full detection instrumentation is in place, these controls reduce the blast radius. Block the delivery mechanism and the LOLBins that stage the payload. Reversible. No agents required.
Quick Wins (Day 0, Free)
  • AppLocker: block unused LOLBins. ClickFix stage-2 loaders are almost exclusively LOLBins (MSHTA, curl, MSIEXEC from user paths). Block every LOLBin your environment does not actively use. This is the single highest-impact control — not just for ClickFix but for the entire LotL attack class.
    See: Windows LOLBIN Hardening playbook for the full ACL + WDAC rollout.
    1–2 daysFree (AppLocker built-in)
  • PowerShell Constrained Language Mode. Restrict PowerShell to CLM for all users who do not require full language mode. The obfuscated one-liner stagers ClickFix uses break under CLM. Configure via AppLocker script rules or WDAC script enforcement.
    Half dayFree
  • Block Win+R / Win+X keyboard shortcuts for non-technical user populations (call centre, finance, HR). This can be done via Group Policy keyboard filter or registry. Test first — some workflows depend on Win+R. A broken shortcut is better than a compromised infostealer host, but confirm scope before deploying broadly.
    2 hoursTest before enforce
  • Add fake CAPTCHA to phishing simulation campaigns. If your phishing simulation vendor supports custom lures, add a ClickFix scenario immediately. Most users have never been trained specifically on fake CAPTCHA attacks — this is the fastest way to establish a baseline click rate before you start awareness training.
    1 hour setupFree (if vendor supports)
Core Engagement (2–3 days)
  • Roll out AppLocker LOLBin policy to all non-developer endpoints. Stage: pilot (25 hosts) → department → fleet. 48-hour observation window between waves. Document every exception with owner and expiry.
  • Enable PowerShell Script Block Logging + Module Logging + Transcription via GPO — three separate toggles. Without all three, the stager’s deobfuscated content is invisible. This is required for detection Loop 2.
  • Segment the Win+R / Win+X shortcut block: non-technical users enforce first, technical users audit-only with heightened monitoring.
Target State

Non-technical user population cannot launch Win+R / Win+X shells. All endpoints have AppLocker LOLBin policy in enforce mode. PowerShell telemetry flows to SIEM. ClickFix scenario included in phishing simulation programme. Stage-2 LOLBin execution blocked for the vast majority of infostealer delivery paths.

2 Detection — Behavioral Signals That Survive Obfuscation
IOC and YARA matching on ClickFix command-line content is obsolete — per-visitor payload uniqueness defeats static signatures. These detection signals are behavioral and process-chain-based. They remain valid regardless of obfuscation variant.
Quick Wins (Day 0, Free)
  • Hunt for PowerShell runspaces. ClickFix payloads deliberately execute inside runspaces to reduce EDR visibility. Runspace creation is visible via PowerShell Event ID 53504 or ETW. The vast majority of endpoints should have zero runspace activity — any hit is high-confidence.
    # Hunt for runspace creation events
    Get-WinEvent -FilterHashtable @{
      LogName='Microsoft-Windows-PowerShell/Operational'; ID=53504
    } -MaxEvents 100 |
      Select TimeCreated,
        @{n='User';    e={$_.UserId}},
        @{n='Message'; e={$_.Message.Substring(0,[Math]::Min(200,$_.Message.Length))}}
    30 minFree
  • Monitor RunMRU for suspicious entries. Win+R execution writes the pasted command to HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. Attackers attempt to clear this key but the clearing itself is a tell. Segment rules: non-technical users have a very narrow expected value set; any PowerShell or encoded blob is high-confidence.
    # Sysmon Rule: monitor RunMRU writes
    # EventID 13 (Registry value set), TargetObject contains RunMRU
    # SIEM: alert on values matching:
    #   powershell | cmd | mshta | base64 | -enc | -e | frombase64
    # Separate rule for non-technical OU: any value that is not a known
    # app path (e.g. "notepad", "calc") = alert
    1 hourFree (Sysmon / registry auditing)
  • Win+X process chain alert. Win+X launches Windows Terminal by default, which opens PowerShell. Alert on: WindowsTerminal.exe spawning powershell.exe which within 60 seconds spawns a LOLBin or makes a first-time outbound connection.
    # Sigma-style logic:
    # ParentImage: '*\WindowsTerminal.exe'
    # Image: '*\powershell.exe'
    # AND within 60s, child process is:
    #   mshta | curl | certutil | bitsadmin | msiexec (from user path)
    #   OR network connection to external IP (Sysmon Event 3)
    2 hoursFree
Core Engagement (2–3 days)
  • Download-folder + RunMRU correlation (new variant). The emerging download-folder staging technique leaves a clean PowerShell command in RunMRU but creates a file in %USERPROFILE%\Downloads\ seconds before. Build a correlation rule: file creation in Downloads folder (Sysmon Event ID 11) from a browser process, followed within 30 seconds by PowerShell execution referencing that same filename.
    # Sysmon Event 11 (FileCreate):
    #   TargetFilename: '*\Downloads\*.exe' OR '*.ps1' OR '*.zip' OR '*.msi'
    #   Image: '*\chrome.exe' | '*\msedge.exe' | '*\firefox.exe'
    # Correlate with: RunMRU write containing matching filename within 30s
  • LOLBin first-time outbound connection. Alert when MSHTA, curl, certutil, or bitsadmin makes an outbound TCP connection to an external IP it has never contacted before. Combine with a 30-day baseline window per endpoint. New destination from a scripting binary = high signal.
  • Multi-file drop to same directory. Infostealer shotgun pattern: multiple executables written to the same %APPDATA% or %TEMP% subdirectory within 60 seconds by the same parent process. Three or more hits in the same path = high confidence infostealer delivery.
  • Explorer child process anomaly. Win+R commands execute as children of explorer.exe. Alert on explorer spawning PowerShell or CMD where the command line contains -enc, -e, FromBase64, iex, DownloadString, or IWR. These are not expected from legitimate Win+R usage.
  • Deobfuscation shortcut for incident response. ClickFix obfuscation is shallow. To dump the deobfuscated payload without executing it: modify the PowerShell command to replace the final invocation with Write-Host. The obfuscated layers evaluate themselves and print the plaintext payload.
Target State

Runspace hunt running continuously in SIEM. RunMRU monitoring segmented by user population (non-technical = high alert, technical = medium). Win+X process chain rule deployed. Download-folder correlation rule active. SIEM alert-to-triage SLA <15 min for any runspace or RunMRU hit.

3 Posture — Application Control and Script Enforcement
AppLocker raises the cost. WDAC closes the door. Script enforcement specifically blocks the obfuscated PowerShell stagers ClickFix relies on — and it is the lowest-risk WDAC deployment phase because it does not touch executable code at all.
Quick Wins (Day 0, Free)
  • WDAC script enforcement first. Unlike full application control, script enforcement only restricts PowerShell, .NET scripts, and WSH. It puts PowerShell into Constrained Language Mode for any script not signed by a trusted publisher. ClickFix stagers almost universally break under CLM. Deploy in audit mode first (Event ID 3076 in Microsoft-Windows-CodeIntegrity/Operational), enforce after one week of clean observation.
    1 day (audit), 1 week (observe), 1 day (enforce)Free (built into Windows)
  • Deploy Microsoft’s Vulnerable Driver Blocklist. Zero false positives, blocks BYOVD attack class used in post-ClickFix lateral movement. Ships with Windows 11 22H2+. For older endpoints, deploy via Intune WDAC policy or GPO.
    2 hoursFree
  • Enable Defender ASR rule: Block execution of potentially obfuscated scripts (5BEB7EFE-FD9A-4556-801D-275E5FFC04CC). Start in audit mode. Directly targets the obfuscated base64 stager pattern that ClickFix relies on.
    30 minFree (Defender)
Core Engagement (3–5 days)
  • Full WDAC application control rollout via Windows LOLBIN Hardening playbook (Loop 3). WDAC blocks renamed LOLBins, enforces driver signing, and survives SYSTEM-level tampering that AppLocker does not. Script enforcement → EXE enforcement → DLL enforcement is the recommended phase order.
  • Deploy via Intune Endpoint Security → Application Control for MDM-managed fleets. Use the built-in “Microsoft’s recommended block list” template as your base, add ISG (Intelligent Security Graph) option to auto-trust reputable software without cataloguing every binary.
  • For MDR customers: base policy deployed centrally (script enforcement + driver blocklist), supplemental policies per customer for their unique software stack. One base policy, N supplemental policies in Intune device groups.
Target State

WDAC script enforcement deployed and enforced on all endpoints. Unsigned PowerShell stagers blocked at kernel level. Microsoft Recommended Block List current. LOLBin AppLocker deny policy versioned in git. Runspace creation from unsigned scripts impossible under CLM.

4 Awareness — Train for the Reflex, Not the Attack
Standard security awareness does not cover fake CAPTCHAs. Users trained to spot suspicious links and email senders have no mental model for a CAPTCHA that tells them to paste a command. This gap is explicit and current.
Quick Wins (Day 0, Free)
  • Add a ClickFix module to your awareness programme now. The awareness gap is documented — most users have been trained on phishing and vishing but not fake CAPTCHAs. One email + one short video is sufficient to create recognition. Key message: a legitimate CAPTCHA never asks you to open a terminal or paste a command.
    2 hours to createFree
  • What to include in training materials:
    • Side-by-side: legitimate Cloudflare CAPTCHA vs ClickFix fake. Spot the difference.
    • The three-step attack: click button → Win+R / Win+X → Ctrl+V → Enter.
    • The visual deception: only the last few characters of the clipboard are visible. The “verification code” is real; the 500 characters before it are not.
    • The rule: if a webpage asks you to press Win+R or open a terminal, close the tab and report it.
  • Update phishing simulation cadence. Add a ClickFix scenario (fake CAPTCHA lure) to your quarterly simulation rotation. Track click rate and execution rate separately: clicking the CAPTCHA button is not the risk; pasting and executing is.
    1–2 hours/quarterFree
Core Engagement (1 day)
  • Run a ClickFix phishing simulation against a representative sample of non-technical users before training. Capture the baseline execution rate. This is the metric that justifies the programme to leadership.
  • Build a reporting flow: a browser bookmark or toolbar button that opens a pre-filled IT report form. Lower the friction for reporting a suspicious CAPTCHA to near zero. Users who recognise ClickFix need an immediate, effortless channel to report.
  • Brief the IT helpdesk on ClickFix. They will receive the “I think I ran something I shouldn’t have” calls. They need a standard triage question: “Did you paste something from a CAPTCHA?” and a clear escalation path to IR.
Target State

Fake CAPTCHA scenario included in phishing simulation programme with baseline execution rate measured. All non-technical staff trained on the Win+R / Win+X pattern. Helpdesk has ClickFix triage script. Reporting rate (users flagging suspicious CAPTCHAs) tracked as a positive metric.

Reference & Tooling

  • ClickFix Hunter — open data project, ~3,500+ confirmed ClickFix cases with domain, date, and command line. Primary research dataset for threat intel and IOC seeding.
  • Windows LOLBIN Hardening playbook — AppLocker ACL stopgap through full WDAC application control. The LOLBin blocking that stage-2 ClickFix loaders hit.
  • LOLBAS project — canonical inventory of living-off-the-land binaries. Every “execute”-tagged entry is a ClickFix stage-2 candidate.
  • MITRE ATT&CK T1204 — User Execution — T1204.004 (Malicious Copy-Paste) is the specific sub-technique for ClickFix-style clipboard delivery. Verify sub-technique number before tagging detections.
  • Microsoft WDAC Recommended Block Rules — maintained list of historically-abused binaries. Subscribe to the GitHub commit feed for updates.

Detection Summary

Signal Source Fidelity
PowerShell runspace creation Event ID 53504 / ETW High
RunMRU: non-technical user, any PowerShell / encoded blob Sysmon Event 13 High
Windows Terminal → PowerShell → LOLBin / outbound Sysmon Event 1 + 3 High
Downloads folder file + RunMRU correlation Sysmon Event 11 + 13 Medium–High
LOLBin first-time outbound connection Sysmon Event 3 + baseline Medium
Explorer child process with encoded PowerShell Sysmon Event 1 Medium
Multi-file drop to same directory within 60s Sysmon Event 11 Medium
Obfuscated strings (emoji / hashtags) in PowerShell ScriptBlock log / Event 4104 Low — attackers retired this
YARA / IOC on command-line content Any Obsolete