Fake CAPTCHA queries spreading malware – BSI warns of ClickFix
Fraudsters are using fake CAPTCHA forms to inject malware onto computers. The BSI is warning of the so-called ClickFix method.

Fake CAPTCHAs as entry point for cybercriminals
Anyone browsing the internet knows the query: click images, tick a box – to prove you're not a robot. Criminals are currently increasingly exploiting precisely this familiar procedure, as swr3.de reports.
Genuine CAPTCHA systems work with four methods: image selection, simple click tests, behaviour-based mouse analysis and acoustic checks as an accessible alternative. What they have in common: they never request a keyboard combination or manual system inputs.
This is exactly what distinguishes legitimate from fraudulent CAPTCHAs. The fake variants pretend that the user must enter a specific keyboard combination for an alleged security check. Anyone who does this transfers the malware to their own computer themselves – the attackers get the victim to attack themselves, so to speak.
Alexandra Bohnert from SWR's IT security management puts the danger in perspective: "The issue is currently relevant because cybercriminals are exploiting something we all know from everyday life."
Attack method with a name: ClickFix and TerminalFix
The method is known under the names "ClickFix" and "TerminalFix" respectively and has been circulating for some time. However, the number of cases is currently increasing again. The Federal Office for Information Security (BSI) has expressly warned against this wave of attacks.
One should be suspicious whenever a CAPTCHA query requests pressing keys, entering commands or confirming system dialogues. Such requests do not come from legitimate security systems.
Act quickly if suspicion arises
Anyone who believes they have fallen for such a trap should act immediately: disconnect the computer from the network, use security software to check it and, if in doubt, call in IT professionals.
Cybercriminals are relying on methods other than fake CAPTCHAs. Police are simultaneously warning of WhatsApp fraud involving fake polls and QR codes: fraudulent messages are sent via hacked accounts and thus appear to be messages from acquaintances.
Source: Google News CH — Crime (de)