Fake CAPTCHA Scam Hijacks Thousands of Small‑Business Websites
- Nishadil
- September 14, 2026
- 0 Comments
- 3 minutes read
- 0 Views
- Save
- Follow Topic
Malware-laden ‘ClickFix’ prompts Windows users to run dangerous commands via bogus CAPTCHAs on over 5,400 sites
More than 5,400 legitimate websites have been compromised to display fake CAPTCHA dialogs that trick Windows users into pasting a malicious command, experts say.
Imagine you’re on a small‑business site you’ve visited before—a local plumber, a boutique coffee shop, or a community nonprofit. The page loads, a familiar logo greets you, and then a CAPTCHA pops up, asking you to prove you’re not a robot.
Sounds routine, right? Not this time. Instead of the usual blurry letters, the dialog tells you to open the Windows Run box (Win+R) and paste a line of text. The message is oddly urgent, promising you’ll “unlock the page” or “verify your access.” Most of us would stop dead in our tracks, but the wording is crafted to sound harmless enough that a moment’s curiosity could lead you straight into trouble.
That’s exactly what security researchers at Netskope Threat Labs have uncovered. In the past few months they traced more than 5,400 compromised websites across roughly 2,200 organizations. The common denominator? A malicious script that swaps a legitimate CAPTCHA for a fake one that lures Windows users into executing a command.
The command itself is tiny—just a few characters—but when run it downloads and installs what the researchers are calling the “ClickFix” malware. Once on a computer, ClickFix can hijack the browser, display additional ads, and even open the door for more serious payloads down the line. In short, a simple copy‑and‑paste can hand over a foothold to cyber‑criminals.
What makes the campaign especially worrying is its low‑tech elegance. The attackers target small‑to‑mid‑size business sites that often lack robust security monitoring. Because the sites appear legitimate, visitors lower their guard. And because the prompt appears as a normal part of the page flow, many users never think to question it.
So, how can you protect yourself?
- Never open Windows Run from a web page. Legitimate sites never ask you to run commands on your computer.
- Look for visual cues. Real CAPTCHAs are usually served by well‑known providers (Google reCAPTCHA, hCaptcha) and include familiar branding.
- Keep your system updated. Security patches often block the download mechanisms these scripts rely on.
- Use reputable security software. Modern antivirus tools can flag the malicious command before it executes.
Website owners aren’t out of luck either. Netskope recommends a quick sweep of all third‑party plugins, especially any that inject scripts into pages, and a thorough review of server logs for unusual outbound calls. Removing the malicious snippet and restoring a clean CAPTCHA service usually shuts the attack down.
In the meantime, stay vigilant. If a CAPTCHA asks you to “open Run” or “paste a command,” walk away and double‑check with the site’s official contact channels. A moment of hesitation can keep your computer—and your data—safe.
- UnitedStatesOfAmerica
- News
- Fnc
- FoxNews
- Article
- Science
- ScienceNews
- FoxNewsTech
- FoxNewsTechTopicsSecurity
- FoxNewsTechTopicsCybercrime
- PhishingScam
- FoxNewsTechTopicsHackers
- FoxNewsTechTopicsVirus
- ClickfixMalware
- WebsiteCompromise
- FakeCaptcha
- WindowsRunCommand
- NetskopeThreatLabs
- SmallBusinessCybersecurity
- MaliciousScript
- BrowserHijack
Editorial note: Nishadil may use AI assistance for news drafting and formatting. Readers can report issues from this page, and material corrections are reviewed under our editorial standards.