Skip to content
Clickfix Attack Uses finger.exe to Deploy Malware via Deceptive CAPTCHA

Clickfix Attack Uses finger.exe to Deploy Malware via Deceptive CAPTCHA

First seen 15 Dec 2025, 12:49 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A new social engineering campaign named ClickFix has been identified, utilizing the Windows command-line tool finger.exe to install malware on users' systems. The attack initiates with a misleading CAPTCHA verification page that tricks users into executing a script, thereby starting the infection process. This technique has been in use since at least November 2025.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 201d ago How this analysis works

More articles in this cluster (4)

Following this threat?

Track ClickFix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed