Scam Radar

How can you recognize ClickFix and EtherHiding: new malware campaign via smart contracts and fake CAPTCHAs?

Published

Listen to the episode

TLDR

A new malware campaign combines the ClickFix and EtherHiding techniques to target business and consumer users. After compromising legitimate websites, attackers inject obfuscated scripts that display a fake CAPTCHA screen or a fraudulent...

How it works

A new malware campaign combines the ClickFix and EtherHiding techniques to target business and consumer users. After compromising legitimate websites, attackers inject obfuscated scripts that display a fake CAPTCHA screen or a fraudulent...

Red flags

  • : Fake CAPTCHA or verification that asks to open the Run dialog or Terminal Instructions to paste and execute PowerShell, cmd, or mshta commands Compromised legitimate websites that redirect to suspicious verification pages What to do: Never paste or execute commands suggested by web pages, CAPTCHAs, or popup windows Be wary of any site that requires the use of Win+R, PowerShell, or Terminal for "verifications" Keep OS, browser, and security solutions up to date, and report suspicious incidents to the relevant CERT

What to do

  1. 1After compromising legitimate websites, attackers inject obfuscated scripts that display a fake CAPTCHA screen or a fraudulent verification page.
  2. 2Red flags: Fake CAPTCHA or verification that asks to open the Run dialog or Terminal Instructions to paste and execute PowerShell, cmd, or mshta commands Compromised legitimate websites that redirect to suspicious verification pages What to do: Never paste or execute commands suggested by web pages, CAPTCHAs, or popup windows Be wary of any site that requires the use of Win+R, PowerShell, or Terminal for "verifications" Keep OS, browser, and security solutions up to date, and report suspicious incidents to the relevant CERT

Source

FAQ

Is ClickFix and EtherHiding: new malware campaign via smart contracts and fake CAPTCHAs a real scam pattern?

Yes. Treat the message, call, or payment request as suspicious until you verify it through an official channel.

What are the first warning signs?

: Fake CAPTCHA or verification that asks to open the Run dialog or Terminal Instructions to paste and execute PowerShell, cmd, or mshta commands Compromised legitimate websites that redirect to suspicious verification pages What to do: Never paste or execute commands suggested by web pages, CAPTCHAs, or popup windows Be wary of any site that requires the use of Win+R, PowerShell, or Terminal for "verifications" Keep OS, browser, and security solutions up to date, and report suspicious incidents to the relevant CERT

What should I do first?

After compromising legitimate websites, attackers inject obfuscated scripts that display a fake CAPTCHA screen or a fraudulent verification page.; Red flags: Fake CAPTCHA or verification that asks to open the Run dialog or Terminal Instructions to paste and execute PowerShell, cmd, or mshta commands Compromised legitimate websites that redirect to suspicious verification pages What to do: Never paste or execute commands suggested by web pages, CAPTCHAs, or popup windows Be wary of any site that requires the use of Win+R, PowerShell, or Terminal for "verifications" Keep OS, browser, and security solutions up to date, and report suspicious incidents to the relevant CERT

Can LegalAudit check my case?

Yes. Start a free chat and paste the message, link, sender, or payment details for triage.