CASE STUDY · CYBERSECURITY

A "fake CAPTCHA" attack,
caught and contained.

One of our client's team members did something millions of people do every day — looked up a supplier's website and clicked through an "are you a robot?" check. This one was fake, and it quietly ran malware built to steal passwords and hijack live logins. Within minutes, our 24×7 threat hunting had spotted it and cut the machine off the network — turning what could have been a serious breach into a contained, no-drama incident.

FocusLayered cybersecurity & 24×7 threat hunting
Threat"Fake CAPTCHA" (ClickFix) malware
OutcomeIsolated in minutes — breach averted
THE SITUATION

An everyday click, weaponised.

There was nothing reckless about it. A staff member searched for a company they deal with, opened what looked like the right website, and was met with a familiar "verify you're human" prompt.

This is a fast-growing style of attack the industry calls ClickFix, or the "fake CAPTCHA." Instead of ticking a box, the page calmly instructs you to press a short sequence of keys as a "verification step." Follow along, and you've unknowingly pasted and run a hidden command on your own computer — no dodgy download, no obvious warning. It preys on the exact habit we've all been trained into: clicking through CAPTCHAs without a second thought.

MINUTE BY MINUTE

How it unfolded — and how fast we caught it.

The attack and our response, step by step. It plays automatically — or hit replay.

REAL INCIDENT · A GENUINE ATTACK ON A CLIENT'S NETWORK — DETAILS REDACTED
    Ready to play…
    WHY IT'S SO DANGEROUS

    The kind of attack antivirus alone misses.

    What makes this technique nasty isn't just the trick — it's how well it slips past traditional defences.

    It looks completely legitimateIt mimics the CAPTCHAs everyone clicks daily. Even careful, security-aware staff can be caught in a busy moment.
    Basic antivirus often misses itThere's no obvious malicious file — the trick misuses trusted, built-in Windows tools to quietly fetch the payload, sailing past signature-based AV.
    It steals more than passwordsThis malware family goes after saved logins and active session tokens — the kind that can bypass multi-factor authentication and hand over an account outright.
    "You can train people all day, but eventually someone, somewhere, will click. Good security assumes that — and is ready to catch it when it happens."
    HOW OUR LAYERED SECURITY RESPONDED

    Spotted, isolated, and shut down — fast.

    This is exactly the moment layered cybersecurity earns its keep. No single tool saved the day; the layers did — working together, around the clock.

    RESULTS & IMPACT

    A contained incident, not a headline.

    MinutesTo detect & isolateThe device was off the network before the malware could spread or exfiltrate data.
    ContainedNo business-wide breachWhat could have become account takeover across the business was stopped at one machine.
    RebuiltClean device returnedA full reimage and credential reset — back to work on a machine they can trust.
    Behaviour-based detectionEDR and threat hunting caught what antivirus signatures would have missed.
    MFA-bypass shut downRevoking sessions closed the stolen-token loophole before it could be used.
    A calmer clientA worrying moment handled quickly and transparently — with a clear explanation of what happened and why.
    "Antivirus alone would have missed this. It was the layers — 24×7 threat hunting, behavioural detection and instant isolation — that turned a potential disaster into a contained incident."
    LAYERS, NOT LUCK

    Would your setup have caught this?

    If your cybersecurity is really just antivirus and hope, an attack like this walks straight in. Book a free IT Health Check and we'll show you, honestly, where you'd stand — and what layered protection actually looks like.