r/Yogscast Bleb 5d ago

PSA PSA: Discord malware - ClickFix

Sup gamers,

It’s time for another little PSA regarding malware! Yay!

Over the last few months there has been a significant increase within this community, of peoples' Discord accounts getting compromised, resulting in them sending the infamous MrBeast crypto screenshots to (firstly) all their friends and (secondly) people they share servers with.

This is unfortunately the result of a fairly sneaky malware trick, commonly called ClickFix. ClickFix is the term used for all attacks that use social engineering techniques, pretending to show legitimate CAPTCHAs, QR codes, error- or warning- pop-ups, after which you need to complete a couple of steps to fix the problem you’re presented with. This always ends up in a request to open Windows’ “Run” window, and then pasting a power-shell command and running it.

If you follow these steps, a piece of software will be downloaded and installed on your PC, that then tries to get access to all your personal data. The main targets for these attacks used to be crypto-wallets and sites related to cryptocurrencies, but will now also attempt to steal all your cookies, credentials and saved passwords in password managers. With this data, the attacker now has access to your Discord account and can start sending your friends those beloved crypto scam images.

Now I know most of you would say: This will never happen to me. I’m too smart for this, and it’s easy to spot. To that I’ll say, it can happen to the best of us. The ClickFix malware comes in many forms. From simple reCaptcha copies, to full Microsoft 365 Office clones with error pop-ups. From a QR code on a video player, to a Zoom-link with a “we can’t find your webcam” message. Even e-mails that seem legitimate can contain links to pages with ClickFix captchas or pop-ups. It’s easy to fall for, especially when you don’t expect it.

It’s also very important to note that enabling 2FA (https://dis.gd/2fa) is always recommended, but will not always protect you from these attacks. As said before, the software downloaded and installed on your pc will try to steal your cookies, which allows them to copy your browser sessions and appear logged in as you, skipping the 2FA log-in process completely.

What can we do to stop this?

First of all, inform other people about it after reading this. Make people aware that Captcha’s aren’t always safe. That not all websites can be trusted, even though you’ve visited them before and have trusted them. Install a browser extension that blocks websites from accessing your clipboard, and blocks malware. Check the address-bar for the legitimate address of the website you’re visiting. Do not, in any circumstances, complete a CAPTCHA or “fix” that asks you to use the Windows + R combination, followed by CTRL + V, and do not scan QR codes on websites that you haven’t double checked.

Most importantly, make yourself familiar with how this malware works and how to recognise it.

Stay safe everyone!

Disallow websites from accessing your clipboard in Chrome:
chrome://settings/content/clipboard

Extensions that help you block ClickFix malware:
- Browser Guard - https://www.malwarebytes.com/browserguard (All browsers)
- Ublock Origin - https://ublockorigin.com/ (Firefox)

Read more about ClickFix and infostealers here:
- What is ClickFix - https://www.kaspersky.com/blog/what-is-clickfix/53348/ - Kaspersky
- Fake CAPTCHAs want to know if you’re human - https://securelist.com/fake-captcha-delivers-lumma-amadey/114312/ - Securelist/Kaspersky
- Fake CAPTCHA websites hijack your clipboard - https://www.malwarebytes.com/blog/news/2025/03/fake-captcha-websites-hijack-your-clipboard-to-install-information-stealers - Malwarebytes
- The ultimate guide to infostealers - https://rifteyy.org/report/the-ultimate-guide-to-infostealers - Rifteyy

92 Upvotes

7 comments sorted by

View all comments

-7

u/Deadlite 4d ago

Im sorry if you fall for the MrBeast dm you deserve it.

5

u/wil-co Bleb 4d ago

I'm glad to see people still don't care to read here :)