The attack is basically getting someone to accidentally run malicious code.
- ctrl + R brings up the Windows "run" dialogue.
- the code executes a powershell command that reaches out to a remote server
- if successful, the remote server answers and you have installed a dropper or something.
Really, you should never do _anything_ like this for any website. You don't need to protect yourself. This is sort of equivalent (in the strict metaphorical sense) of getting a call from your bank and they ask you for your banking password: you just never do it, no matter what. Same thing here. You don't ever execute code via the run dialogue to solve a CAPTHCA. Never.
https://www.sentinelone.com/blog/how-clickfix-is-weaponizing...
I think the concern is the user not knowing they're executing code on their machine.
And as a counterexample: some captchas require you to compute something expensive to prove you're not a llm scraper or whatever. It's normal for captchas to require you to execute code on your machine, it's just usually done within the browser's sandbox.
And anyway, these things are completely incomprehensible to non-technical users.
I've never run into one of these. What do they ask you to compute?
For that matter, there's always a risk of downloading/installing anything from anywhere. There have been successful compromises of many application supply chains at this point in official release paths. You will accept some risk regardless of your approach.
Just that simple practice has kept me reasonably safe, even from an AI scam once.
Because thousands of users make the same mistake, blame needs to be directed at Windows UX.
MS could fix this easily by 1) moving Run to optional features and 2) removing online features from Start to make performance comparable.
The other "run" interfaces (terminal, conhost, Powershell) are sufficiently menacing to scare away non-devs already.
As a workaround, is it possible to disable Ctr+R to add some friction in case I am distracted?
Oh yeah? What about Google saying “install the reCAPTCHA app in the App Store” <https://reclaimthenet.org/google-broke-recaptcha-for-de-goog...>?
It’s absurd, but these nominally-security tools frequently genuinely train users to become susceptible to attacks.
You saw something unusual, then
1. Stopped what you were doing.
2. Investigated to see if this was legitimate or malicious.
3. Identified a place to asked others about it.
4. Formulated a good question with enough background information to help people answer it.
All around good job! Well done.
Given that the asker isn’t experienced enough to know for sure, erring on the side of giving all the information was the right call. If they didn’t, someone would be riding them about “how are we suppose to know if you don’t show us?”.
"Great instincts!" lmao
It’s the best sandbox I have near at hand for investigating things like that.
Was the site itself actually infected(hacked)? If not, then all you need is adblock (like ublock origin). And that was true for last 20 years.
If website actually got hacked then I don't know of any good solutions. It will be flagged soon or later, and new visitors will be blocked by "Google Safe Browsing". Using something like "Qubes OS" might protect you against attacks based on browser zero-days but VMs don't really protect against ClickFix when people usually share clipboard between host and client VMs.
Or you could send them to download some spyware/adware Play Store app
I've seen similar before where it wasn't the page itself that injected it - rather it was injected by a compromised/sold extension that has permissions on all pages.
It even supports Macs. But the Mac clipboard content is just "Oops...".
P.S.: even worse: the crookedtimber site itself is infected. No third-party attack. It registers a service worker on the user's browser that stays even when you leave the site. Be sure to clean up the storage data after visiting that site.
It then spins up the ClickFix attack - limited to one time per day. I haven't dug into the payload given by the ClickFix attack yet.
For people that have visited while it exists:
1. On Chrome go to chrome://serviceworker-internals search for crookedtimber and unregister the ServiceWorker
2. On Firefox go to about:debugging#/runtime/this-firefox, search for crookedtimber and unregister the ServiceWorker.
If you want to be even safer - just clear all local data for CrookedTimber.
As you might imagine, these attacks are aimed at less sophisticated users who may have no idea what Win+R even does, and who might be tricked into believing that this actually has anything to do with website verification.
The site you visited -- or one of the resources it depends on -- might have been compromised. If you're enterprising, you could probably determine where the malicious script is getting loaded from by looking in the page source.
But I guess if it was loaded via mshta it will respond with a different payload.
Now watch the people with "overabundance of caution" tell me what I did was stupid...
No, the MP3 file is the payload, mshta ignores the binary noise and executes the HTML in it. The HTML is in the middle of the file (search for "DOCTYPE") and it contains an obfuscated VBScript.
Skipping many steps in the whole chain (registering a scheduled task to be executed 1 second later, disabling TLS certificate verification, corrupting the antimalware scan, deobfuscation/decryption, evasion delays, in-memory PE loading, etc.), it as a whole, roughly speaking:
- downloads second stage payload from gpurq.gravityzone.army/{id}
- downloads an image from i.ibb.co/Q7yqNJpr/init-block.jpg (public image hosting) with a steganographically hidden third stage payload
- decrypts and loads a native PE32, heavily obfuscated and without imports
Almost, recently. I bought a new Mac, needed something reliable to carry around. I never had a Mac or anything from Apple before, so I wasn't familiar with how exactly does it work. I knew homebrew existed, I understood it's similar to Linux/Windows in that not all applications are in the store, but wasn't familiar at all with how those are commonly installed.
Here's what I did:
1. Open Safari, the only browser there was.
2. Typed "claude mac download" in the search bar (needed Cowork).
3. Clicked the first link.
4. Copied the command it told me to, instructing me to run it in terminal.
Only now I realize that there's something fishy about the command; it had base64 payload in it. Didn't run it and took closer look on the page - it was a Claude share (which I quickly scrolled over).
I can admit mistakes, but Google, Apple and Anthropic deserve some blame here, too.
- Google: pushed malware link up top, didn't (distinctly, at least) mark it as a paid result and I'd swear it didn't show me the URL (which I usually always check before clicking, but maybe I just missed it as the search results are rendered differently from Kagi's)
- Safari: hides path by default, so all you see is "claude.ai". Someone probably thought this looked nice, I think it's just borderline idiotic.
- Anthropic: hosts what's essentially a user-content on their main domain.
Also recently saw a few legit projects using base64 in their install one-liners. Please, stop it.
> How do you protect yourself ?
Installed not Safari and made Google not my default search engine, as I always do. That way I at least always know where I am.
Endless vigilance. Scammers are always working on new tricks. You were rightly suspicious and not fooled by this one.
As a "end-user" one of the most effective way is to either disable js, which isn't the most practical thing for most of us. You can also use ublock-origin, it doesn't only block ads! You can also throw a lying-DNS in the chain, either by using something like Quad9 or a local resolver with appropriate blocklists (think of unbound or for a more user-friendly solution piehole)
Also an anti-virus can help detect the usual stealer that will be dropped by these FakeCaptcha/ClickFix attack, but they are also easily bypassed, that's why you need multiple layers of protection : each of them can and will fail