Warning: Don’t Fall for Fake CAPTCHAs
You have seen CAPTCHAs hundreds of times.
“Prove you’re human.”
Tick a box.
Select a few traffic lights.
Slide a puzzle.
Then carry on to the website.
That familiarity is exactly what criminals are now exploiting.
Fake CAPTCHA pages increasingly imitate services such as:
Google reCAPTCHA
Cloudflare verification
browser security checks
document verification pages
But instead of simply asking you to click a box, they instruct you to do something that a legitimate CAPTCHA should never require.
That might be:
Press Windows + R
Press Ctrl + V
Press Enter
or:
Open Terminal and paste this command
or even:
Send this pre-written text message to verify yourself.
If a “CAPTCHA” asks you to do any of those things:
stop immediately.
A genuine CAPTCHA does not need you to run commands on your computer.
The Bigger Threat: ClickFix
One of the most widespread fake-CAPTCHA techniques is known as ClickFix.
The page might look convincing.
You see:
Verify you are human
and click a button.
But the website secretly places a command into your clipboard.
It then instructs you to:
1. Press Windows + R.
2. Press Ctrl + V.
3. Press Enter.
It claims this completes the verification.
It does not.
You have just pasted and executed a command supplied by an attacker.
Microsoft describes ClickFix as a social-engineering technique that tricks people into running malicious commands through Windows Run, PowerShell or Terminal, often under the guise of a CAPTCHA, error message or security verification.
Why This Attack Works
The clever part is that the malicious website does not necessarily exploit Windows directly.
It persuades you to run the attack.
That creates an unusual security problem.
The browser may have prevented the site from directly launching PowerShell.
Windows may have prevented the website from installing software itself.
So the attacker asks you to:
open the trusted Windows tool
and:
paste the malicious instruction yourself.
Microsoft says ClickFix can sometimes get past traditional automated defences precisely because the user voluntarily performs the execution steps.
That is what makes the technique so effective.
What Does the Command Actually Do?
The exact payload varies.
A malicious command may attempt to download and execute:
information-stealing malware
remote-access trojans
credential stealers
malware loaders
additional scripts
Microsoft has observed ClickFix campaigns delivering credential-stealing malware and remote-access tools, while Proofpoint has documented fake CAPTCHA campaigns delivering malware including Lumma Stealer and other payloads.
An information stealer can potentially target:
saved browser passwords
browser cookies
cryptocurrency information
authentication tokens
files
cloud credentials
That can turn one fake CAPTCHA into a much broader business-security incident.
The Page May Look Extremely Convincing
Do not assume you will immediately recognise one.
Attackers can imitate:
Cloudflare
Microsoft
document-sharing services
video meeting platforms
browser warnings
Microsoft has even observed ClickFix kits being sold to criminals with selectable visual templates and multiple languages.
The page might therefore look almost exactly like a verification process you have seen before.
The appearance is not the important clue.
The requested behaviour is.
The Three Biggest Red Flags
A legitimate CAPTCHA should not tell you to:
Open Windows Run
For example:
Windows + R
This opens a powerful Windows interface capable of launching applications and commands.
Paste something you cannot see or understand
If the page tells you to press:
Ctrl + V
without clearly showing what you are pasting, that should immediately stop you.
Open PowerShell, Terminal or Command Prompt
No normal website human-verification process requires terminal access.
If a web page claims:
“Open PowerShell to prove you're human”
it is not a normal CAPTCHA.
Close the page.
What About “Press Windows + R, Ctrl + V, Enter”?
This sequence is now important enough that employees should recognise it immediately.
If a website asks for:
Windows + R → Ctrl + V → Enter
assume the page is malicious unless you have an extremely unusual, independently verified reason to believe otherwise.
Microsoft Security Intelligence specifically describes this sequence as a core behaviour of ClickFix attacks.
There is no legitimate reason a CAPTCHA should need the Windows Run dialog.
Fake CAPTCHAs Are Still Evolving
This is not a static scam.
In January 2026, Microsoft observed a variant called CrashFix.
Instead of merely displaying a fake verification page, the attacker deliberately caused the browser to crash or become unusable.
The user was then shown instructions supposedly explaining how to restore normal browser operation.
Those instructions actually led towards malicious command execution.
This is an important evolution because it creates urgency:
“My browser is broken—I need to fix it.”
The attacker is no longer only exploiting familiarity.
They are exploiting panic and problem-solving behaviour.
Fake CAPTCHAs Can Affect Macs Too
This is not purely a Windows issue.
Microsoft has observed ClickFix-style social engineering being used against macOS users as well, including campaigns involving macOS information-stealing malware.
A Mac user might instead be told to:
open Terminal
paste a command
install a package
run a downloaded application
The principle is exactly the same.
A website should not require you to execute a terminal command to prove you are human.
The SMS Version Still Matters
The current Hamilton Group article discusses another fake-CAPTCHA variation:
“Send this text message to confirm you're human.”
That is also a major warning sign.
A malicious page can prepare an SMS and persuade you to send it to:
premium-rate numbers
international destinations
attacker-controlled services
Potential consequences include:
unexpected charges
recurring premium services
information leakage
So the rule is broader than just PowerShell:
A CAPTCHA should not make you leave the webpage and perform an unrelated action on your device.
That includes:
sending SMS messages
calling telephone numbers
opening Run
launching Terminal
installing software
How Do People Reach These Pages?
Not everyone who lands on a malicious CAPTCHA has deliberately visited a suspicious website.
Microsoft and Proofpoint have documented delivery through routes including:
phishing links
compromised websites
malicious advertising
drive-by redirects
fake documents
malicious HTML attachments.
That is important for staff training.
You cannot simply tell employees:
“Don't visit dodgy websites.”
A legitimate website can itself be compromised.
The better defence is teaching people to recognise abnormal behaviour after the page loads.
A Real CAPTCHA Should Stay in the Browser
This is probably the simplest awareness rule.
Normal verification might ask you to:
tick a box
select pictures
solve a puzzle
wait for a browser security check
But everything happens inside the browser page.
It should not require:
Windows Run
PowerShell
Terminal
Command Prompt
a text message
or:
a software download.
That is an easy rule employees can remember.
What Should You Do if You See One?
Do not follow the instructions.
Close the browser tab.
If the page will not close normally:
Alt + F4 on Windows
or quit the browser through the operating system.
If necessary, open Task Manager:
Ctrl + Shift + Esc
and close the browser.
Then reopen it.
Do not restore the suspicious tab if the browser offers:
Restore previous session.
What If You Clicked the CAPTCHA but Did Not Paste Anything?
That is generally much less serious.
A ClickFix page may have copied something malicious to your clipboard.
Clear it simply by copying something harmless.
For example, highlight a word from a safe document and press:
Ctrl + C
Then close the malicious page.
If you did not run the supplied command, the primary execution step may not have occurred.
Still notify IT in a business environment so the link/domain can be investigated and blocked where necessary.
What If You Pasted the Command but Did Not Press Enter?
Close the Run box or Terminal without executing it.
Do not press Enter.
Clear the clipboard.
Notify IT if this happened on a business device.
Again, the important distinction is whether the command was actually executed.
What If You Already Pressed Enter?
Treat the machine as potentially compromised.
Do not simply close the window and carry on.
For a business device:
1. Disconnect it from the network where appropriate.
2. Contact IT/security immediately.
3. Tell them exactly what happened.
4. Provide the suspicious URL if available.
5. Do not start deleting files or clearing logs.
6. Avoid entering new passwords on the potentially compromised PC.
An IT/security team may need to investigate:
PowerShell activity
process execution
downloaded payloads
Microsoft Defender alerts
browser history
endpoint telemetry
stolen credentials
The objective is to determine whether the command actually downloaded or executed malware.
Changing Your Password May Not Be Enough
If information-stealing malware ran, an attacker may potentially obtain more than a password.
Depending on the malware, stolen information could include:
authentication cookies
tokens
saved credentials
browser data
That means remediation may require:
password reset
session revocation
MFA review
endpoint remediation
account monitoring
Do not assume:
“I changed my Microsoft 365 password, therefore everything is safe.”
Investigate the device too.
Why Antivirus Alone Is Not Enough
Security products remain extremely important.
Microsoft Defender now detects ClickFix-related behaviours, and Microsoft classifies several ClickFix-related detections as severe.
But the technique demonstrates why technical protection alone cannot solve social engineering.
If an employee voluntarily launches a legitimate Windows component and runs a command supplied by an attacker, the attack begins inside a trusted tool.
This is why organisations need both:
technical controls
and:
staff awareness.
What Businesses Can Do
A sensible defence includes:
modern endpoint detection and response
web filtering
email security
browser protections
restricting unnecessary administrative privileges
staff awareness training
rapid incident-reporting procedures
Microsoft also recommends reducing unnecessary access to tools such as the Windows Run dialog where business requirements allow it, alongside educating users to recognise ClickFix lures.
The objective is not to ban every Windows administration tool.
It is to make successful social-engineering execution harder.
The Five-Second Fake CAPTCHA Test
Before following any CAPTCHA instruction, ask:
Does this stay entirely inside the webpage?
If yes, it may be legitimate.
If it asks you to:
press Windows + R
paste clipboard contents
open PowerShell
open Terminal
install something
send a text
call a number
stop.
That is not normal human verification.
The Rule Employees Should Remember
If your organisation communicates only one thing about fake CAPTCHAs, make it this:
> No legitimate CAPTCHA needs you to run a command on your computer.
That sentence is far more useful in 2026 than simply telling people to look for badly designed websites.
Modern fake CAPTCHA pages can look convincing.
The strange instruction is the giveaway.
How Hamilton Group Can Help
Fake CAPTCHA and ClickFix attacks are a good example of why cyber security needs both technology and trained employees.
Hamilton Group can help businesses with:
cyber-security awareness training
phishing protection
Microsoft Defender
endpoint detection and response
Microsoft 365 security
web and email protection
security monitoring
incident response
account-compromise investigations
If an employee has already followed a fake CAPTCHA and executed a command, treat it as a potential security incident rather than simply closing the browser.
Visit hgmssp.com or call 0330 043 0069 to discuss cyber-security training and protection.