Known malicious kitcriticalphishing

ClickFix FakeCAPTCHA — LOLBin variant (msiexec/mshta/wmic/etc.)

family: clickfix-fakecaptcha

Same fake-CAPTCHA flow as the PowerShell variant but the copied command is a non-PowerShell Windows LOLBin (msiexec /i <URL>, mshta, wmic, certutil, regsvr32, curl, iex, Invoke-Expression). First validated live on 00c29c34fd.nxcli.io from threatfox's IClickFix-tagged feed (scan 52b189eb / 2f465516 / f6c071f8). Markup-tolerant string matchers (<b>R</b> / <b>V</b> / <b>Enter</b>) catch kits whose instruction text is HTML-formatted.

Anchors

YARA ruleDetect_ClickFix_FakeCaptcha_LOLBin

Provenance

Added: 2026-05-27 10:49
YARA-anchored. Sister to the PowerShell rule under the same family slug.

Sightings (7)

HostScanScriptMatchWhen
norediam.comca791ac9https://norediam.com/traffic/apiyara2026-08-26 12:42
norediam.com444ecfbfhttps://norediam.com/traffic/apiyara2026-08-26 11:21
norediam.coma7182413https://norediam.com/traffic/apiyara2026-08-26 07:23
gangesjute.come33f85f1https://gangesjute.com/wp-content/plugins/one/assets/js/captcha-loader.js?ver=2.0.0yara2026-08-15 03:10
00c29c34fd.nxcli.iof6c071f8https://00c29c34fd.nxcli.io/#htmlyara2026-05-27 10:47
00c29c34fd.nxcli.io2f465516https://00c29c34fd.nxcli.io/#htmlyara2026-05-27 10:43
00c29c34fd.nxcli.io52b189ebhttps://00c29c34fd.nxcli.io/#htmlyara2026-05-27 10:43