Clickfix Attack Uses finger.exe to Deploy Malware via Deceptive CAPTCHA

Clickfix Attack Uses finger.exe to Deploy Malware via Deceptive CAPTCHA

First seen 15 Dec 2025, 12:49 UTC GbhackersCyberpressCybersecuritynewsHackread 75% similarity 40.3

Article Content

Browse articles
ThreatCluster

A new social engineering campaign named ClickFix has been identified, utilizing the Windows command-line tool finger.exe to install malware on users' systems. The attack initiates with a misleading CAPTCHA verification page that tricks users into executing a script, thereby starting the infection process. This technique has been in use since at least November 2025.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story