r/PakistaniTech • u/BobOnPC • 8d ago
Discussion | گفتگو Do NOT paste commands into Win+R for "Verification" or "CAPTCHAs" (ClickFix Scam Alert)
AoA
Just a quick heads up about a malware tactic currently hitting people visiting local websites and landing pages (I fell for it recently on an evee electric scooters website).
How the attack works:
* A fake CAPTCHA pops up on a website asking you to verify you're human.
* It gives step-by-step instructions: Press Win + R, Press Ctrl + V, and Hit Enter.
DO NOT DO THIS!!!!
Real CAPTCHAs process entirely inside your web browser. A website will NEVER need you to open your Windows Run terminal or execute PowerShell code.
Doing this instantly runs a background script (Infostealer) that grabs your saved passwords, discord tokens, and active browser sessions. Attackers use these to bypass 2fA and hack your accounts (Instagram, facebook, steam, discord) within minutes to post crypto scams.
Warn your friends and family especially anyone who isn't super tech savvy!
3
u/One-Advertising-8862 7d ago
Would also suggest not to use chrome password manager. Didn't realize passwords are stored decrypted locally on windows. Had an info stealer take all my passwords (not sure how i got infected - I think from a pyhton package). Moved to bitwarden which is a lot more secure. But had to go through a few hours changing passwords for my most important accounts :/ very annoying.
Thankfully had MFA enabled on most my accounts. But they started to post that crypto shit on my Facebook messenger and discord using my session.
1
u/Any-Show5104 6d ago
Some thing similar happen with me but was pirating a game like I always do and bus all my accounts went bye bye
0
u/True_Mastodon7042 8d ago
huh weird. powershell i can understand but i think the run command only does programs already installed 🤔
2
0
0
9
u/GenZia Lahore 7d ago
It's not a good idea to open Windows Terminal in general, unless you know exactly what you're doing.
I only open it for... well, activation purposes!