ClickFix (FakeCaptcha) campaigns are coercing Windows users into pasting attacker-supplied commands into the Run dialog, turning fake verification prompts into initial-access vectors. Recent activity has delivered the Node.js-based ChainScript RAT through msiexec.exe and Spotify-, Zoom-, or Teams-themed MSI installers; ChainScript persists via a scheduled task and Run key, uses Polygon smart contracts to discover WebSocket C2 servers, and supports shells, file operations, screen capture, wallet discovery, payload deployment, updates, and cleanup. A separate SmartApeSG-branded lure installed an unidentified RAT and persisted MeshAgent from %LocalAppData%\Temp% to connect with a malicious Mesh server.
Another ClickFix chain used caret-obfuscated Run-dialog commands, copied and renamed curl.exe, retrieved a purported PDF containing the legitimate IronPython 3.4.2 ZIP, and executed an in-memory Python payload through a renamed interpreter. The payload contacted artides[.]net with the K8VGmQTrzX User-Agent, disabled TLS certificate validation, then reportedly injected into a restarted explorer.exe and installed a low-level keyboard hook. Defenders should prioritize process-creation and RunMRU telemetry for explorer.exe spawning mshta.exe, cmd.exe, PowerShell, pwsh.exe, or conhost.exe, particularly with encoded commands, download cradles, clipboard activity, obfuscation, or unusual child processes; correlated DNS and mshta.exe detections improve resilience against easily changed lures and command strings.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Blackpoint Cyber’s Adversary Pursuit Group published analysis of ChainScript, a previously unreported Node.js RAT found during a ClickFix investigation. The malware used malicious MSI installers, scheduled-task or Run-key persistence, and Polygon smart-contract lookups to resolve rotating WebSocket C2 infrastructure.
A SmartApeSG-branded fake verification page used ClickFix instructions to infect Windows hosts with an unidentified RAT and MeshAgent. MeshAgent ran from AppData\Local\Temp, persisted on affected hosts, and communicated with a malicious Mesh C2 server.
A ChainScript-associated Polygon smart contract was deployed 23 seconds before creation of its corresponding MSI, ComponentTask33, suggesting an automated build pipeline for the malware infrastructure.
ShroudCloud published the stable, high-severity Sigma rule “FakeCaptcha Clipboard Injection via Explorer” for Windows process-creation telemetry. The rule detects Explorer-spawned interpreters and utilities with download, clipboard, encoded-command, and obfuscation indicators associated with ClickFix activity.
Proofpoint coined the name “ClickFix” for the FakeCaptcha-style social-engineering technique in which victims are instructed to paste malicious commands into the Windows Run dialog.
A ClickFix intrusion used a caret-obfuscated Run-dialog command to retrieve a batch script through finger.claudeam[.]com on TCP/79, download and disguise IronPython 3.4.2, and execute an in-memory Python payload from artides[.]net. About five minutes after initial execution, telemetry recorded injection into restarted explorer.exe and installation of a global low-level keyboard hook.
ShroudCloud detailed ClickFix/FakeCaptcha activity and proposed Sigma detections for suspicious DNS traffic, Explorer-spawned command interpreters, and anomalous mshta.exe behavior. The report also recommended layered detection and RunMRU telemetry for visibility into pasted Run-dialog commands.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
meetcyber.net
Open sourcemalware-traffic-analysis.net
Open sourcecyberveille.ch
Open sourceshroudcloud.io
Open sourceshroudcloud.io
Open sourceshroudcloud.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.