Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Malicious fake CAPTCHAs on thousands of small-business sites lure users into malware

Thousands of legitimate small-business websites have been hijacked to display fake CAPTCHAs that instruct visitors to run commands, leading to malware infection.

Netskope Threat Labs uncovered a campaign compromising more than 5,400 websites belonging to small businesses such as clinics, plumbers and online stores. The malicious code injects a fake CAPTCHA that appears normal but then directs users to open the Windows Run dialog and paste a command, a social-engineering method dubbed ClickFix. To avoid takedown, the attackers store command instructions in a smart contract on the BNB Smart Chain test network, allowing compromised sites to fetch updates without altering each site.

A newer variant uses WebRTC to create an encrypted channel and deliver payloads directly in the browser. Researchers observed several hundred active compromised sites each day, with over 300 contacting the malicious infrastructure on weekdays. Victims are urged to avoid running any commands from webpages, keep software updated, and verify the integrity of their CMS installations.

Why it matters

Everyday websites can be weaponized to trick users into installing malware, endangering both consumers and small businesses.

In this story

fake captchamalwarecompromised websitesClickFixblockchainWebRTCWindows Runsmall businesssecurity researchers
Get the beta ↗