Fake CAPTCHA Checks Masking Dangerous ‘ClickFix’ Cyber Scam, Kerala Police Issue Alert

THIRUVANANTHAPURAM: Cybercriminals are finding clever new ways to trick everyday internet users, and their latest trick comes hidden behind something most people run into every single day: a standard CAPTCHA check.

Kerala Police have issued an urgent warning regarding a dangerous cyber attack known as ‘ClickFix,’ which tricks victims into handing over full control of their computers to remote hackers.

CAPTCHA prompts normally serve as a simple security test to verify if a site visitor is a real human rather than an automated bot.

However, scammers are now embedding fake CAPTCHA pop-ups on compromised or malicious websites.

Once a user clicks through the initial verification, a deceptive dialogue box suddenly appears on the screen, claiming that the site has encountered a technical glitch.

The pop-up instructs the user to copy a specific line of code and paste it manually into their system to complete the check and fix the issue.

Believing this to be an official instruction from the website, many users follow the prompt step by step, unwittingly opening the door to malicious software.

Once executed, the pre-programmed malware installs silently, giving remote hackers full administrative access to the compromised machine.

From there, the attackers can steal personal files, block system operations, and harvest sensitive data stored inside web browsers.

This includes saved online banking passwords, email credentials, and social media login details, putting victims at severe risk of financial loss and privacy theft.

In some cases, the fraudsters deploy ransomware to lock down the entire system and demand hefty payments to restore access.

They often threaten to delete vital files or release private documents online if the ransom goes unpaid, causing immense mental distress.

Police clarified that no legitimate website will ever ask users to open PowerShell or Command Prompt, nor will they require running manual commands or downloading special files to clear a CAPTCHA check.

Anyone who suspects their machine has been infected should immediately disconnect the device from the internet by switching off Wi-Fi and pulling out the LAN cable to cut off the attacker’s access.

Suspicious links or files should never be forwarded to other computers or mobile phones for checking, as doing so can spread the virus across network devices.

If a system is compromised, victims should bring the device directly to the nearest cyber police station for technical examination by experts.

Anyone falling victim to online financial fraud should report the incident immediately within the ‘golden hour’ by calling the cyber helpline at 1930 or lodging a complaint at www.cybercrime.gov.in.

Leave a Reply

Your email address will not be published. Required fields are marked *