Fake Captchas as security vulnerability: BSI warns after Berlin government hack
After a cyberattack on Berlin's administrative network, the BSI has warned of manipulated Captcha queries that introduce malware.

BSI warning after Berlin government hack: How fake Captchas work
Following a cyberattack on the IT state network of Berlin's administration, the Federal Office for Information Security (BSI) has warned of an increasingly widespread attack method using manipulated Captcha queries. According to radiobielefeld.de, hackers likely gained access to the government network via a fake "Confirm that you are human" query.
How to recognise a genuine Captcha
A legitimate Captcha grants access to the respective website immediately after ticking the box — without further prompts. However, anyone who receives additional instructions after the mouse action, such as instructions to execute keyboard combinations in conjunction with Windows Terminal or PowerShell windows, has landed on a compromised or manipulated page, according to BSI.
In this case, according to the BSI: stop immediately and close the browser. Those affected may have either directly encountered a dangerous site or been deliberately lured there via phishing or social engineering.
Attack method "Clickfix" known since 2024
The method is known in professional circles as "Terminalfix" or "Clickfix". It first appeared in 2024. Microsoft had already warned of these attack forms at the end of August before the BSI highlighted the danger again in connection with the Berlin incident.
The deception becomes apparent at the latest when the fake Captcha page demands specific keyboard combinations for alleged further verification. Anyone who executes these commands opens access to their own system for hackers.
How the attack works in detail
After accessing a manipulated or compromised website, the user is presented with what appears to be a normal Captcha. After interaction, further instructions appear that prompt the entry of keyboard combinations — for example, opening a PowerShell session via the Windows key in combination with other keys. If the user carries out these steps, malware is installed on the computer in the background.
In the event of infection: Complete reinstallation recommended
Anyone who has actually become a victim of such an attack should, according to BSI recommendations, completely reinstall their computer. Many malware programmes of this type make far-reaching changes to the operating system that cannot easily be undone. In such cases, simply removing the detected malware is generally not sufficient to restore complete system integrity.
Source: Google News LU DE