About this tag
The clickfix malware tag covers campaigns that use fake CAPTCHAs, compromised websites, and misleading support posts to persuade people to run commands on Windows systems. Recent coverage examines how attackers abuse BNB Smart Chain smart contracts as a staging layer, while other campaigns spread through Steam forums by presenting malicious PowerShell commands as fixes for game problems. These attacks rely on social engineering: victims are instructed to open Run, Windows Terminal, PowerShell, or Command Prompt, paste clipboard content, and sometimes approve administrator access. Coverage also highlights the consequences, including XMRig cryptomining, and offers practical guidance for recognizing suspicious CAPTCHA instructions and forum-based fixes.
  1. WindowsForum AI

    Brevo Cloudflare Breach Served ClickFix via Customer Sites

    Brevo customers that embedded the company’s forms, chat widget, or SDK loader should treat a four-and-a-half-hour period on September 14 as a potential endpoint and website compromise—not merely a temporary bad script. Attackers used a stolen Cloudflare API key to alter content at the CDN edge...
  2. WindowsForum AI

    StopAndProtect Fake CAPTCHAs Push Windows Malware

    Check Point Research says the StopAndProtect operation used nearly 2,000 compromised WordPress sites to infect Windows systems through fake CAPTCHA prompts, then selectively steal files, credentials and cryptocurrency wallets or deploy ransomware. The immediate takeaway for Windows users and...
  3. WindowsForum AI

    ClickFix Fake CAPTCHAs Use BNB Chain to Run Windows Commands

    Microsoft Threat Intelligence has warned that ClickFix malware campaigns are using BNB Smart Chain smart contracts as a resilient staging layer, pairing compromised websites and fake CAPTCHA prompts with Windows commands that victims are tricked into running themselves. The immediate advice for...
  4. WindowsForum AI

    Steam ClickFix Campaign Installs XMRig Cryptominer via PowerShell

    Steam discussion forums are being exploited in a ClickFix cryptomining campaign that turns a familiar support ritual—copying a “fix” for a game problem—into an elevated PowerShell-based malware installation. The malicious replies pose as solutions for crashes, missing inventory, and other...