CAPTCHA Bypass and ClickFix Lures Drive Surge In Credential Theft Attacks

CAPTCHA-bypass lures and ClickFix-style social engineering are helping credential thieves get past both users and security tools, and the latest Q1 2026 data shows these tactics are becoming more common.

Microsoft Threat Intelligence says email phishing remained massive in scale, but attackers increasingly favored link-based delivery, QR code lures, and CAPTCHA-gated pages to steal credentials.

Microsoft recorded about 8.3 billion email-based phishing threats in the first quarter of 2026, with monthly volume easing from 2.9 billion in January to 2.6 billion in March.

CAPTCHA Bypass and ClickFix Lures

Link-based messages made up 78% of email threats, while malicious payloads fell from 19% in January to 13% in February and March, showing a clear move toward hosted phishing infrastructure.

QR code phishing was the fastest-growing tactic, more than doubling over the quarter, and it reached its highest monthly level in at least a year by March.

Tycoon2FA monthly malicious messages volume (November 2025 – March 2026) (Source: microsoft)
Tycoon2FA monthly malicious messages volume (November 2025 – March 2026) (Source: microsoft)

Credential theft remained the main goal behind malicious payloads throughout the quarter.

Microsoft said this shift suggests threat actors preferred phishing pages hosted online rather than payloads that render locally on a victim’s device.

That approach can make attacks faster to deploy and harder for security tools to catch early.

Top TLDs and second-level domains (2LDs) associated with Tycoon2FA infrastructure (November 2025 – March 2026) (Source: microsoft)
Top TLDs and second-level domains (2LDs) associated with Tycoon2FA infrastructure (November 2025 – March 2026) (Source: microsoft)

CAPTCHA-gated phishing also surged sharply in March, jumping 125% to 11.9 million attacks after declines in January and February.

Attackers rotated among HTML, PDF, SVG, DOC/DOCX, and email-embedded URL delivery methods, which suggests active testing to find the most effective bypass path.

Microsoft also observed that the share of CAPTCHA-gated sites hosted on Tycoon2FA infrastructure fell to 41% in March, showing the tactic is spreading beyond one platform.

Trend of QR code phishing attacks by weekly volume (November 2025 – March 2026) (Source: microsoft)
Trend of QR code phishing attacks by weekly volume (November 2025 – March 2026) (Source: microsoft)

One major theme in the quarter was the use of fake CAPTCHA pages to delay analysis and push users into interacting with the attack.

Microsoft also noted ClickFix-style abuse, where fake verification prompts trick users into copying or executing malicious commands instead of simply entering credentials.

A separate early-2026 campaign described fake CAPTCHA lures as a way to deliver a stealthy information stealer, reinforcing how effective the technique has become.

Tycoon2FA remained a key example of how disruption can hurt phishing operations, at least temporarily.

After Microsoft’s Digital Crimes Unit and partners moved against its infrastructure in early March, associated email volume dropped 15% for the rest of the month, and access to active phishing pages was reduced.

The platform later shifted hosting providers and registration patterns, but Microsoft described that as partial recovery rather than a full return to prior scale.

Business email compromise was still widespread too, with about 10.7 million attacks in the quarter.

Most of those messages were low-effort and generic, which shows attackers are using both sophisticated phishing kits and simple social engineering at the same time.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories