Security researchers reported an active malware distribution technique that abuses bogus CAPTCHA pages to trick users into executing attacker-supplied commands on Windows. In the ClearFake campaign analyzed by Expel, victims land on a compromised site and are instructed to press Win + R, then paste and run a clipboard-seeded command—an approach commonly referred to as ClickFix—which results in malicious PowerShell execution. The campaign emphasizes living-off-the-land tradecraft and evasion, including proxy execution by abusing the trusted Windows script C:\Windows\System32\SyncAppvPublishingServer.vbs to launch PowerShell in hidden mode and reduce the chance of AV detection.
Separate measurement and telemetry on the same broader tactic found large-scale infrastructure supporting fake CAPTCHA lures: a Censys analysis identified 9,494 breached websites hosting counterfeit verification pages, with ~70% appearing nearly identical. The most common infection mechanisms involved clipboard manipulation leading to VBScript and PowerShell execution (with significant counts of each observed), alongside other delivery paths such as MSIEXEC-based installation of malicious Windows Installer packages. Researchers also observed use of the Matrix push command-and-control framework to support fileless deployment, noting that these intrusions can leave no traditional executable artifacts and may evade signature-based detection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Researchers reported a new ClickFix-style campaign that abuses the signed Microsoft App-V script SyncAppvPublishingServer.vbs instead of launching PowerShell directly. The attack used a public Google Calendar ICS file as a dead-drop resolver, then staged in-memory payloads that ultimately launched Amatera Stealer.
Expel researchers disclosed that ClearFake uses fake CAPTCHA prompts to trick users into pasting malicious PowerShell commands from the clipboard into the Windows Run dialog. They also described the campaign's use of the legitimate SyncAppvPublishingServer.vbs script for hidden proxy execution and estimated nearly 150,000 infections since August 2025.
Censys analysis found 9,494 compromised websites serving bogus CAPTCHA pages used for malware distribution. Researchers observed several delivery chains, including clipboard-injected PowerShell and VBScript, MSIEXEC-based installers, and Matrix Push for fileless deployment.
On November 18, 2025, Darktrace observed likely ClearFake activity on a single device, including mshta.exe execution, Smart Chain-related requests, and attempts to retrieve payloads from suspicious infrastructure. Darktrace said its Autonomous Response blocked the outbound connections and likely prevented delivery of an information stealer.
Based on smart-contract transaction history, Expel assessed that the ClearFake campaign had been infecting systems since August 2025. The operation used EtherHiding on the Binance Smart Chain and other resilient hosting methods to support large-scale malware delivery.
ClearFake was first identified in mid-2023 as a malicious campaign using injected JavaScript on compromised websites, often WordPress sites, to trick users with fake browser update and CAPTCHA-style lures. Victims were commonly driven to these sites through SEO poisoning.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
darktrace.com
Open sourcerescana.com
Open sourcethehackernews.com
Open sourcesecurityonline.info
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.