A sophisticated social engineering campaign targets Windows users via fake CAPTCHA verification pages , delivering StealC malware to steal sensitive information. The attack begins when users visit compromised websites that mimic Cloudflare's security system, tricking them into executing PowerShell commands that install the malware.

This campaign combines psychological manipulation with advanced obfuscation techniques, creating a particularly dangerous cybercrime scenario.
The Method: From CAPTCHA to Malware
The attack starts from seemingly legitimate websites that have been compromised. Malicious JavaScript loads a fake CAPTCHA page, tricking users into executing the command Windows + R → Ctrl + V → Enter, believing they are completing a standard security check. This method, known as ClickFix, exploits users' trust to launch StealC.
See also: OysterLoader: The "silent" malware loader that worries experts
LevelBlue researchers observed that the chain includes:
- Download shellcode.
- Loading custom 64-bit PE loader.
- StealC injection into legitimate Windows processes, such as svchost.exe.
What does StealC steal?
Malware mainly targets:
- Browser credentials (Chrome, Edge, Firefox).
- Cryptocurrency wallet extensions (MetaMask, Coinbase Wallet).
- Steam account logs and Outlook emails .
- System information and screenshots.
Collecting this information can lead to identity theft, account access, and financial loss.

Chain of infection and concealment techniques
StealC uses fileless execution, remaining in memory and reducing the chances of detection by antivirus. After the initial PowerShell command, it downloads shellcode via the Donut, loads the PE loader, and injects the final payload into a legitimate process.
Communication with the command and control server is via HTTP traffic encrypted with Base64 and RC4, while a double layer of string obfuscation protects critical data such as C2 server URLs, file paths, and database queries.
See also: Lazarus campaign plants malicious npm and PyPI packages
Signs and warnings for organizations
Network administrators should monitor:
- Suspicious User-Agent strings like “Loader”.
- Run PowerShell with coded commands.
- VirtualAlloc and CreateThread patterns indicating shellcode injection.
- Unusual access to browser credential databases .
Detecting these elements can limit the spread and impact of StealC.
User protection
Basic defense includes:
- Avoid clicking on CAPTCHAs or notifications that look suspicious.
- Update the system and antivirus.
- Use multi-factor authentication for accounts.
- Educate users not to execute manual PowerShell commands without confirmation.
The combined use of technological measures and user education is critical to preventing such advanced attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: AMOS infostealer targets macOS via popular AI app

The evolution of social engineering
The ClickFix campaign with StealC shows how social engineering is evolving alongside encryption and obfuscation techniques . User trust is being used as an attack tool, making education and vigilance key to Windows security.
The combination of psychological manipulation and technical sophistication makes it clear that organizations must continually strengthen malware detection and prevention protocols, especially in environments that handle sensitive user data.
