Fake CAPTCHA tests hijack Windows PCs through malicious commands
Microsoft has issued a warning to Windows users about a rising cyber threat disguised as fake CAPTCHA tests. Hackers are exploiting the familiarity of CAPTCHA verification pages to trick victims into executing malicious commands, turning a routine security check into a dangerous trap. This campaign, dubbed "ClickFix," is becoming increasingly convincing, making it difficult for users to identify the warning signs.
The attack begins when a user visits a compromised website that displays a fraudulent verification or repair window. Unlike legitimate CAPTCHA services that operate within the browser, this malicious prompt instructs users to copy a snippet of text, open the Windows Run dialog box, paste the content, and press Enter. This action grants attackers direct access to the victim's computer.
What makes this campaign particularly dangerous is its ability to bypass traditional antivirus software. Before the fake CAPTCHA interaction, the compromised site secretly downloads a malicious script disguised as a harmless image file into the browser's cache. The command pasted into the Run box then renames this file into a script and launches it silently, avoiding detection by download scanners.
Once launched, the script uses administrative tools like PowerShell and Windows Management Instrumentation (WMI) to gather system information, steal sensitive data, and set up long-term control over the infected system. Microsoft advises users to rely on built-in protections like Microsoft Defender SmartScreen and Defender for Endpoint, which can block known malicious sites and flag suspicious behavior.
The key to staying safe is recognizing that no legitimate CAPTCHA or browser verification service will ever ask users to copy and paste commands into system dialogs. Any such request should be treated as a potential attack.