Description

A malware delivery operation is using deceptive browser prompts that imitate familiar Google and Cloudflare security checks. The activity is associated with the ClickFix technique and has been used to deliver StealC, HijackLoader, NetSupport RAT, and several other malicious components. Instead of exploiting a software flaw, the attackers rely on misleading instructions that convince users to perform actions on their own Windows systems, resulting in the execution of harmful PowerShell commands. During the attack, users are shown counterfeit CAPTCHA screens, meeting-related error messages, or fabricated browser validation notices. The displayed instructions direct victims to open a system utility and run content supplied by the webpage. In some cases, attacker-controlled data is placed into the clipboard, making it easier for the victim to paste and launch the command. The malicious pages may appear through previously breached web resources, attacker-created sites, or externally hosted web content. After the command is launched, PowerShell connects to remote systems and retrieves additional scripts or installation files. Subsequent stages may collect host details, create new folders, alter registry settings, and maintain access after a restart. Different delivery packages, including MSI files, compressed archives, executable loaders, and hijacked DLL loading paths, are used to install the selected payload. Some observed attack sequences include attempts to interrupt endpoint protection tools, obtain elevated execution, and run malicious components within trusted Windows processes. The overall activity demonstrates how convincing visual impersonation and guided user actions can be combined to install credential-stealing and remote-access malware without depending on conventional exploit-based delivery methods.