CrowdStrike warns of rising ClickFix social engineering attacks
CrowdStrike researchers have reported an uptick in 'ClickFix' attacks, a social engineering technique where users are tricked into copying and running malicious commands under the pretense of troubleshooting common IT issues. The company observed that groups like STARDUST CHOLLIMA and VOODOO BEAR have used ClickFix in real-world incidents. CrowdStrike's data show a 563% rise in fake CAPTCHA-related attack attempts in 2025.
- ClickFix attacks use fake error or CAPTCHA prompts
- Victims instructed to copy and run malicious commands
- CrowdStrike attributes attacks to multiple threat groups
- Incident rate for fake CAPTCHAs rose 563% in 2025
Sources covering this
In this story
More in Cybersecurity
Critical zero-days in Citrix NetScaler exploited, patches released
Citrix has confirmed that two critical zero-day vulnerabilities affecting NetScaler ADC and Gateway devices have been exploited.
Dutch police arrest former hacker in ShinyHunters probe
Dutch police have arrested Pepijn van der Stap, a previously convicted hacker, in connection with an ongoing investigation into the…
Apple fixes CoreGraphics flaw after targeted attacks
Apple has released security updates for iOS, iPadOS, and macOS to fix a CoreGraphics vulnerability that may have been used in highly…
New Spectre BTR attack exposes Linux root password hashes
Researchers have unveiled a new Spectre Variant 2 attack, named Branch Target Reuse (BTR), that can extract root password hashes from…