Early Times Report
Jammu, Sept 27: A new breed of cyber fraud is spreading fast, and it doesn't need to hack into your device — it convinces you to hack it yourself. Security researchers are sounding the alarm over "ClickFix," a deceptively simple scam technique that has exploded across the internet in recent months, tricking everyday users into personally installing the very malware that goes on to empty their bank accounts, steal their passwords and hijack their digital lives. The scam thrives on a single, brutal irony: instead of breaking through firewalls or exploiting software flaws, criminals simply ask the victim, politely and convincingly, to do the damage themselves. The Jammu and Kashmir Police's Cyber Crime Wing has issued a public advisory warning residents against a fast-spreading cyber fraud technique known as "ClickFix," which is tricking internet users into unknowingly installing malware on their own devices — often resulting in the theft of banking credentials, passwords and other sensitive personal information. According to the advisory, cybercriminals are deploying fake CAPTCHA verification prompts, bogus browser error messages, and fraudulent software update notifications to lure unsuspecting users. These deceptive pop-ups instruct victims to open system tools such as PowerShell, Command Prompt, the Windows Run dialog box, or Terminal on Mac devices, and paste in a command that has been secretly copied to the clipboard beforehand. Police said th These deceptive pop-ups instruct victims to open system tools such as PowerShell, Command Prompt, the Windows Run dialog box, or Terminal on Mac devices, and paste in a command that has been secretly copied to the clipboard beforehand. t the moment this command is executed, malware is silently installed on the device — capable of stealing banking details and login credentials, and in some cases granting cybercriminals remote access to the victim's system altogether. "No genuine CAPTCHA, browser error, or verification process will ever ask a user to open a system window and paste a command into it. If any website makes such a request, users must stop immediately and close the page," the advisory stated, describing this as the clearest warning sign of the scam. The Cyber Crime Wing has also cautioned citizens to be wary of pop-ups mimicking official interfaces such as Google Chrome, Microsoft Word, or Windows Update, and advised against clicking on suspicious advertisements or unfamiliar verification links. The advisory further urged the public to keep antivirus software and operating systems updated, and to never share OTPs, banking passwords, or other credentials with anyone. Police have appealed to victims of cyber fraud to report incidents without delay, stressing that swift action greatly improves the chances of freezing fraudulently transferred funds. Citizens have been directed to call the National Cyber Crime Helpline at 1930 or file a complaint online at cybercrime.gov.in. The advisory concluded with an appeal to the public to remain vigilant while browsing the internet and to share the warning widely among family members, colleagues and community groups to help prevent further victimisation. |