Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands
Microsoft Threat Intelligence warns of a ClickFix campaign in which compromised websites show fake CAPTCHA-style prompts tricking Windows users into executing malicious commands. The operation stages its payload in the browser cache, evading download-based detection and working around Windows Run dialog character limits.