HomeSecurityiClicker site breach targeted students via CAPTCHA

iClicker site hack targeted students via CAPTCHA

The website of iClicker, a popular student interaction platform, was compromised by a ClickFix-style attack, which used a fake CAPTCHA window to trick students and faculty into installing malware on devices .

See also: ClickFix: COLDRIVER hackers distribute LOSTKEYS malware

iClicker violation

iClicker, a subsidiary of Macmillan , is a digital classroom tool that allows teachers to record attendance, ask live questions or polls, and track student engagement . It is widely used by 5,000 teachers and 7 million students at colleges and universities across the United States, including the Universities of Michigan, Florida, and various institutions in California.

According to a security alert from the Safe Computing , the iClicker website was compromised between April 12 and 16, 2025, to display a fake CAPTCHA that asked users to click "I'm not a robot" to verify their identity.

However, when visitors clicked on the verification prompt, a PowerShell was silently copied to the Windows clipboard, as part of a social engineering attack known as “ClickFix.”

The fake CAPTCHA then instructed users to open the Windows “ Run ” window (Win + R), paste the PowerShell script there (Ctrl + V), and execute it by pressing Enter to “ verify .” Although the ClickFix attack is no longer running on the iClicker website, a user on Reddit ran the command via the Any.Run platform , revealing the PowerShell payload that is triggered

See also: MintsLoader distributes GhostWeaver via Phishing, ClickFix

The PowerShell command used in the iClicker attack was heavily disguised, but when executed, it connected to a remote server at https://67.217.228[.]14:8080 to download and execute a second PowerShell script. Unfortunately, it is not known which malware was ultimately installed, as the second script varied depending on the type of visitor.

iClicker site hack targeted students via CAPTCHA
iClicker site hack targeted students via CAPTCHA

For targeted visitors, the system sent a script that downloaded malware to the computer. The University of Michigan reports that the malware allowed the attacker to gain full access to the infected device.

For those not targeted—such as malware analysis sandboxes—the script downloaded and executed the genuine Microsoft Visual C++ Redistributable. ClickFix-style attacks have evolved into widespread social engineering attacks, used in many malicious campaigns, including those that fake Cloudflare CAPTCHAs, Google Meet, or browser errors.

Based on previous campaigns, it is likely that the attack was spreading an infostealer, which can steal cookies, credentials, passwords, credit card information, and browsing history from browsers such as Google Chrome, Microsoft Edge, Mozilla Firefox , and other Chromium-based programs.

See also: Lazarus hacker group adopts ClickFix attacks

A related and crucial point to the above is that these types of attacks are mainly based on user deception and not on a technical security gap. That is, attackers exploit users’ trust in well-known platforms (such as iClicker or alleged Cloudflare CAPTCHAs) and their usual behavior (e.g. clicking “I’m not a robot” or following verification instructions). This shows how important it is to educate users on cybersecurity issues, especially in the education sector, where students and teachers are a frequent target of such campaigns.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS