Skip to main content

Warning: Don’t Fall for Fake CAPTCHAs

Media

 

You have seen CAPTCHAs hundreds of times.

“Prove you’re human.”

Tick a box.

Select a few traffic lights.

Slide a puzzle.

Then carry on to the website.

That familiarity is exactly what criminals are now exploiting.

Fake CAPTCHA pages increasingly imitate services such as:

Google reCAPTCHA

Cloudflare verification

browser security checks

document verification pages


But instead of simply asking you to click a box, they instruct you to do something that a legitimate CAPTCHA should never require.

That might be:

Press Windows + R

Press Ctrl + V

Press Enter

or:

Open Terminal and paste this command

or even:

Send this pre-written text message to verify yourself.

If a “CAPTCHA” asks you to do any of those things:

stop immediately.

A genuine CAPTCHA does not need you to run commands on your computer.

The Bigger Threat: ClickFix

One of the most widespread fake-CAPTCHA techniques is known as ClickFix.

The page might look convincing.

You see:

Verify you are human

and click a button.

But the website secretly places a command into your clipboard.

It then instructs you to:

1. Press Windows + R.


2. Press Ctrl + V.


3. Press Enter.

 

It claims this completes the verification.

It does not.

You have just pasted and executed a command supplied by an attacker.

Microsoft describes ClickFix as a social-engineering technique that tricks people into running malicious commands through Windows Run, PowerShell or Terminal, often under the guise of a CAPTCHA, error message or security verification.

Why This Attack Works

The clever part is that the malicious website does not necessarily exploit Windows directly.

It persuades you to run the attack.

That creates an unusual security problem.

The browser may have prevented the site from directly launching PowerShell.

Windows may have prevented the website from installing software itself.

So the attacker asks you to:

open the trusted Windows tool

and:

paste the malicious instruction yourself.

Microsoft says ClickFix can sometimes get past traditional automated defences precisely because the user voluntarily performs the execution steps.

That is what makes the technique so effective.

What Does the Command Actually Do?

The exact payload varies.

A malicious command may attempt to download and execute:

information-stealing malware

remote-access trojans

credential stealers

malware loaders

additional scripts


Microsoft has observed ClickFix campaigns delivering credential-stealing malware and remote-access tools, while Proofpoint has documented fake CAPTCHA campaigns delivering malware including Lumma Stealer and other payloads.

An information stealer can potentially target:

saved browser passwords

browser cookies

cryptocurrency information

authentication tokens

files

cloud credentials


That can turn one fake CAPTCHA into a much broader business-security incident.

The Page May Look Extremely Convincing

Do not assume you will immediately recognise one.

Attackers can imitate:

Cloudflare

Google

Microsoft

document-sharing services

video meeting platforms

browser warnings


Microsoft has even observed ClickFix kits being sold to criminals with selectable visual templates and multiple languages.

The page might therefore look almost exactly like a verification process you have seen before.

The appearance is not the important clue.

The requested behaviour is.

The Three Biggest Red Flags

A legitimate CAPTCHA should not tell you to:

Open Windows Run

For example:

Windows + R

This opens a powerful Windows interface capable of launching applications and commands.

Paste something you cannot see or understand

If the page tells you to press:

Ctrl + V

without clearly showing what you are pasting, that should immediately stop you.

Open PowerShell, Terminal or Command Prompt

No normal website human-verification process requires terminal access.

If a web page claims:

“Open PowerShell to prove you're human”

it is not a normal CAPTCHA.

Close the page.

What About “Press Windows + R, Ctrl + V, Enter”?

This sequence is now important enough that employees should recognise it immediately.

If a website asks for:

Windows + R → Ctrl + V → Enter

assume the page is malicious unless you have an extremely unusual, independently verified reason to believe otherwise.

Microsoft Security Intelligence specifically describes this sequence as a core behaviour of ClickFix attacks.

There is no legitimate reason a CAPTCHA should need the Windows Run dialog.

Fake CAPTCHAs Are Still Evolving

This is not a static scam.

In January 2026, Microsoft observed a variant called CrashFix.

Instead of merely displaying a fake verification page, the attacker deliberately caused the browser to crash or become unusable.

The user was then shown instructions supposedly explaining how to restore normal browser operation.

Those instructions actually led towards malicious command execution.

This is an important evolution because it creates urgency:

“My browser is broken—I need to fix it.”

The attacker is no longer only exploiting familiarity.

They are exploiting panic and problem-solving behaviour.

Fake CAPTCHAs Can Affect Macs Too

This is not purely a Windows issue.

Microsoft has observed ClickFix-style social engineering being used against macOS users as well, including campaigns involving macOS information-stealing malware.

A Mac user might instead be told to:

open Terminal

paste a command

install a package

run a downloaded application


The principle is exactly the same.

A website should not require you to execute a terminal command to prove you are human.

The SMS Version Still Matters

The current Hamilton Group article discusses another fake-CAPTCHA variation:

“Send this text message to confirm you're human.”

That is also a major warning sign.

A malicious page can prepare an SMS and persuade you to send it to:

premium-rate numbers

international destinations

attacker-controlled services


Potential consequences include:

unexpected charges

recurring premium services

information leakage


So the rule is broader than just PowerShell:

A CAPTCHA should not make you leave the webpage and perform an unrelated action on your device.

That includes:

sending SMS messages

calling telephone numbers

opening Run

launching Terminal

installing software


How Do People Reach These Pages?

Not everyone who lands on a malicious CAPTCHA has deliberately visited a suspicious website.

Microsoft and Proofpoint have documented delivery through routes including:

phishing links

compromised websites

malicious advertising

drive-by redirects

fake documents

malicious HTML attachments.


That is important for staff training.

You cannot simply tell employees:

“Don't visit dodgy websites.”

A legitimate website can itself be compromised.

The better defence is teaching people to recognise abnormal behaviour after the page loads.

A Real CAPTCHA Should Stay in the Browser

This is probably the simplest awareness rule.

Normal verification might ask you to:

tick a box

select pictures

solve a puzzle

wait for a browser security check


But everything happens inside the browser page.

It should not require:

Windows Run

PowerShell

Terminal

Command Prompt

a text message

or:

a software download.

That is an easy rule employees can remember.

What Should You Do if You See One?

Do not follow the instructions.

Close the browser tab.

If the page will not close normally:

Alt + F4 on Windows

or quit the browser through the operating system.

If necessary, open Task Manager:

Ctrl + Shift + Esc

and close the browser.

Then reopen it.

Do not restore the suspicious tab if the browser offers:

Restore previous session.

What If You Clicked the CAPTCHA but Did Not Paste Anything?

That is generally much less serious.

A ClickFix page may have copied something malicious to your clipboard.

Clear it simply by copying something harmless.

For example, highlight a word from a safe document and press:

Ctrl + C

Then close the malicious page.

If you did not run the supplied command, the primary execution step may not have occurred.

Still notify IT in a business environment so the link/domain can be investigated and blocked where necessary.

What If You Pasted the Command but Did Not Press Enter?

Close the Run box or Terminal without executing it.

Do not press Enter.

Clear the clipboard.

Notify IT if this happened on a business device.

Again, the important distinction is whether the command was actually executed.

What If You Already Pressed Enter?

Treat the machine as potentially compromised.

Do not simply close the window and carry on.

For a business device:

1. Disconnect it from the network where appropriate.


2. Contact IT/security immediately.


3. Tell them exactly what happened.


4. Provide the suspicious URL if available.


5. Do not start deleting files or clearing logs.


6. Avoid entering new passwords on the potentially compromised PC.

 

An IT/security team may need to investigate:

PowerShell activity

process execution

downloaded payloads

Microsoft Defender alerts

browser history

endpoint telemetry

stolen credentials


The objective is to determine whether the command actually downloaded or executed malware.

Changing Your Password May Not Be Enough

If information-stealing malware ran, an attacker may potentially obtain more than a password.

Depending on the malware, stolen information could include:

authentication cookies

tokens

saved credentials

browser data


That means remediation may require:

password reset

session revocation

MFA review

endpoint remediation

account monitoring


Do not assume:

“I changed my Microsoft 365 password, therefore everything is safe.”

Investigate the device too.

Why Antivirus Alone Is Not Enough

Security products remain extremely important.

Microsoft Defender now detects ClickFix-related behaviours, and Microsoft classifies several ClickFix-related detections as severe.

But the technique demonstrates why technical protection alone cannot solve social engineering.

If an employee voluntarily launches a legitimate Windows component and runs a command supplied by an attacker, the attack begins inside a trusted tool.

This is why organisations need both:

technical controls

and:

staff awareness.

What Businesses Can Do

A sensible defence includes:

modern endpoint detection and response

web filtering

email security

browser protections

restricting unnecessary administrative privileges

staff awareness training

rapid incident-reporting procedures


Microsoft also recommends reducing unnecessary access to tools such as the Windows Run dialog where business requirements allow it, alongside educating users to recognise ClickFix lures.

The objective is not to ban every Windows administration tool.

It is to make successful social-engineering execution harder.

The Five-Second Fake CAPTCHA Test

Before following any CAPTCHA instruction, ask:

Does this stay entirely inside the webpage?

If yes, it may be legitimate.

If it asks you to:

press Windows + R

paste clipboard contents

open PowerShell

open Terminal

install something

send a text

call a number


stop.

That is not normal human verification.

The Rule Employees Should Remember

If your organisation communicates only one thing about fake CAPTCHAs, make it this:

> No legitimate CAPTCHA needs you to run a command on your computer.

 

That sentence is far more useful in 2026 than simply telling people to look for badly designed websites.

Modern fake CAPTCHA pages can look convincing.

The strange instruction is the giveaway.

How Hamilton Group Can Help

Fake CAPTCHA and ClickFix attacks are a good example of why cyber security needs both technology and trained employees.

Hamilton Group can help businesses with:

cyber-security awareness training

phishing protection

Microsoft Defender

endpoint detection and response

Microsoft 365 security

web and email protection

security monitoring

incident response

account-compromise investigations


If an employee has already followed a fake CAPTCHA and executed a command, treat it as a potential security incident rather than simply closing the browser.

Visit hgmssp.com or call 0330 043 0069 to discuss cyber-security training and protection.