Phishing Series 2026: ClickFix Fake-CAPTCHA Clipboard-to-PowerShell Execution Chain

Detects a suspicious execution chain where a browser process makes a network connection, followed shortly by a direct execution of command-line tools (powershell.exe, mshta.exe, or cmd.exe) from the Windows explorer.exe process (e.g., via the Run dialog). This behavior is characteristic of 'ClickFix' social engineering attacks where users are tricked into copying and pasting malicious commands from a web page directly into their local environment.