Known malicious kitcriticalphishing

Windows ClickFix: fake 'Windows Security' verification dialog (Win+R, mshta) — page code

family: clickfix-windows-security-dialog-2026-10

Compromised websites whose homepage is replaced, for Windows visitors only, by a fake reCAPTCHA-style checkbox that opens a 'Windows Security — Human verification required' dialog. The dialog copies a command to the clipboard and tells the visitor to press Windows key + R, paste with Ctrl+V and press Enter. The command uses mshta to download an executable from a file-sharing link, save it as %TEMP%\verification.exe and run it; the payload has been reported as an information stealer. Closing the dialog only makes it reappear. Visitors on macOS or a phone see the normal website, so site owners rarely notice. Seen on 2026-10-01 on unrelated WordPress sites at three hosting providers, all serving the same page. No legitimate verification step asks visitors to run a command.

Anchors

YARA ruleClickFix_Windows_Security_Dialog_Kit

Provenance

Added: 2026-10-01 19:51
Page rule keyed on the kit's own element ids, function and constant names and comments, not on the payload link, the file name or the command, so it still matches after a payload swap. The general ClickFix LOLBin rule also fires on these pages; this entry names the kit.

Sightings (3)

HostScanScriptMatchWhen
acmaturaky.cz76f6d43b…https://acmaturaky.cz/#htmlyara2026-10-01 19:51
datahousemarketing.comafb9f1d1…https://datahousemarketing.com/#htmlyara2026-10-01 19:51
niluhomeimprovement.com539be8c1…https://niluhomeimprovement.com/#htmlyara2026-10-01 19:51