Microsoft warns fake CAPTCHA is tricking Windows users into running malware
Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.
The takeaway: Microsoft has identified a new malware campaign that uses fake CAPTCHA prompts to trick Windows users into running malicious commands. The campaign, called TerminalFix, is a variation of the ClickFix attacks that have become increasingly common among business users. The campaign highlights a broader security problem: familiar browser prompts can now bypass technical safeguards by convincing users to execute the attacker's code themselves.
The pages impersonate Cloudflare and other trusted services. Instead of presenting a normal CAPTCHA challenge, they instruct users to open PowerShell or Command Prompt and paste in a command.
That is the main difference between TerminalFix and earlier ClickFix activity. ClickFix attacks often direct victims to the Windows Run dialog, where a command is used to install an information stealer. TerminalFix, by contrast, uses PowerShell or Command Prompt,...
Copyright of this story solely belongs to techspot.com. To see the full text click HERE