Özel Fırsat 6 ay ÜCRETSİZ — kupon kodu EXTRACopied!
UYGULA >>

Trust.Zone Blog

Trust.Zone'dan En Son Haberler, Etkinlikler ve Özel Teklifler

Beware of Fake CAPTCHAs: A Security Check That Steals Passwords

9 Eylül 2026

A video is about to start, but a verification screen appears first. It looks familiar: a checkbox, a security logo and a message asking to confirm that a real person is visiting. Most people have completed enough of these checks to follow the instructions without much thought.

Then comes an extra step. The page asks to open a Windows tool and paste a command. It sounds unnecessary, but the instructions are clear and the video is waiting. Following them can install malicious software instead of completing a security check.

This is a fake CAPTCHA scam. It uses a routine part of browsing to persuade people to do something they would normally avoid: run instructions from an unknown source.

Why the check looks trustworthy

A genuine CAPTCHA helps a website separate human visitors from automated bots. It might involve selecting pictures, ticking a box or waiting for the browser to finish checking the connection. The process is familiar, even when it is frustrating.

A fake version copies that appearance and adds a believable explanation. Verification has failed. The browser needs a quick fix. One more step will open the page. A professional design and a familiar security logo can make those instructions seem official.

The website itself may also be familiar. Attackers can place a fake check on a compromised site, sometimes without its owner knowing. That makes the requested action more useful to judge than the name or appearance of the website.

What happens after the click

In a common version of the scam, clicking a button copies a command to the clipboard. The page then gives instructions to open Windows Run or PowerShell, paste the command and execute it. That command can download and launch malware. Netskope researchers have documented this process in fake CAPTCHA attacks.

Security researchers call this technique ClickFix. The name describes the idea: present a problem, then persuade the visitor to carry out the supposed fix. There may be no normal installation screen or obvious warning about the software being downloaded.

The useful rule is straightforward. A CAPTCHA should never require a command to be pasted into Windows Run, PowerShell or Terminal. There is no need to understand the command to recognise that something is wrong.

The risk goes beyond the page

Malware running on a computer may collect saved passwords, personal files or browser data. This means an account can be at risk even if no password was entered on the suspicious website.

Some malware steals session data, which helps websites remember that an account is already signed in. If that data is usable, an attacker may be able to access the account without going through the usual login process.

Meanwhile, the computer may appear to work normally. Even if the video plays after the fake check, that reveals nothing about what else the command installed.

A note for VPN users

Some websites may show a CAPTCHA while a VPN is active. These checks also appear on regular connections, and browser settings can cause them to repeat, as Cloudflare explains in its verification guidance. A CAPTCHA alone is no reason to give up VPN protection.

Pay attention to the instructions, even when another check feels routine. Selecting pictures or ticking a box is familiar. Opening a system tool or installing a “verification program” is a reason to close the page.

How to respond to a suspicious check

Close any verification page that asks for system commands, unknown software or disabled security protection. If it claims the browser needs updating, check through the browser’s own settings. For a download, return to the developer’s official website.

Clicking a button is different from executing a command. If the interaction stopped at the button, close the page and replace suspicious clipboard content by copying harmless text. Do not paste it into a command window to investigate.

If a command was executed, disconnect the affected computer from the internet and stop using it for sensitive accounts. Run a full scan with trusted, updated security software. On a work device, contact the IT team and describe what happened.

Use a separate, clean device to secure important accounts, starting with email. Change affected passwords, review recent activity and sign out other sessions where possible. Get technical help if the computer’s condition remains uncertain before entering new passwords on it.

Share: