Beware of the LegionLoader malware being distributed via the ClickFix method

Published September 11, 2026

LegionLoader malware is being sent to users via fake Cloudflare CAPTCHA pages. Attackers trick people into running PowerShell commands that download and install the malware, which can steal Chrome passwords and run other harmful code on your computer.

Report priority
High
Targets
spear phishing+3 more

How it works

  • Attackers send fake CAPTCHA pages to users via two methods: malicious links on Korea's Newlywed Hope Town Namu Wiki and fake emails pretending to be internal business system account instructions.
  • When users click these links, they see a fake CAPTCHA page that tricks them into running PowerShell commands.
  • These commands download and run LegionLoader malware, which then steals Chrome browser passwords and can run other harmful code on your computer.

What to do

If you clicked a link on Korea's Newlywed Hope Town Namu Wiki or opened a fake email pretending to be an internal business system account instruction, check your Chrome browser for unexpected password changes or unfamiliar sites in your browsing history. If you see anything suspicious, your computer may have been infected with LegionLoader malware.

If you suspect your computer is infected, run a full antivirus scan using a trusted security program like Windows Defender or Malwarebytes. If you clicked a malicious link or opened a fake email, reset your Chrome passwords immediately and monitor your accounts for unusual activity. If you are unsure whether your computer is infected, contact your IT department or a trusted cybersecurity professional for help.

Technical details

Affected software: spear phishing, clickfix, legionloader, fake captcha

Attackers sent fake CAPTCHA pages to users via malicious links on Korea's Newlywed Hope Town Namu Wiki and fake emails pretending to be internal business system account instructions. When users clicked these links, they were tricked into running PowerShell commands that downloaded and installed LegionLoader malware, which stole Chrome passwords and ran other harmful code on their computers.

LegionLoader malware is distributed via ClickFix tactics, where attackers impersonate Cloudflare CAPTCHA pages to trick users into running malicious PowerShell commands. Two primary attack vectors have been observed: one leverages fake links on Korea's Newlywed Hope Town Namu Wiki page, while the other uses spear-phishing emails posing as internal business system account issuance instructions. When victims interact with these malicious links, they're redirected to spoofed CAPTCHA pages that execute PowerShell scripts, which then download and deploy LegionLoader.

Once active, LegionLoader decrypts and executes shellcode and PE files, checks the victim's environment (including display device and ASN verification), and installs a backdoor capable of running arbitrary payloads, such as PE files, shellcode, PowerShell scripts, and MSI installers. The malware also steals Chrome browser credentials and profile data based on commands from its command-and-control (C2) server. The threat was tracked under OTX-6aa3fef84a7f54f4ae325151.