Fake CAPTCHA Scams Hijack Thousands of Small‑Business Sites to Push Malware
- Nishadil
- September 14, 2026
- 0 Comments
- 3 minutes read
- 0 Views
- Save
- Follow Topic
Malicious “CAPTCHA” Prompts Trick Windows Users Into Running Dangerous Commands
Over 5,400 legitimate websites now serve bogus CAPTCHA dialogs that tell visitors to paste a command into Windows Run, handing over malware with a single click.
Imagine you’re on the homepage of a neighborhood bakery, scrolling past the menu, when a tiny box pops up asking you to prove you’re human. It looks exactly like a normal CAPTCHA – those squiggly letters you type in to prove you’re not a bot. Only this one says, “Open Windows Run and paste the code below.” If you follow the instructions, you just handed the site a back‑door to your computer.
That’s the reality for users across the globe right now. Security researchers at Netskope Threat Labs have uncovered a massive campaign that has compromised more than 5,400 websites belonging to over 2,200 separate organizations. Most of the affected sites are tiny local‑business pages – think coffee shops, dental offices, and boutique stores – places you’d never suspect of harboring malicious code.
The attack works like a charm because it exploits a habit we all have: when a CAPTCHA appears, we’re already primed to type something. By swapping the usual text‑entry field for a short instruction to open the Windows Run dialog (Windows + R) and paste a command, the hackers turn a benign security check into a malware delivery mechanism. The command typically points to a script that silently downloads and installs a trojan known as “ClickFix.” Once installed, ClickFix can steal credentials, inject further ads, or even enlist the infected machine in a botnet.
What makes this campaign especially insidious is its scale and low cost. The attackers simply purchase cheap hosting, inject the fake CAPTCHA code, and let the traffic do the rest. Because the compromised sites are legitimate and often rank high in local search results, unsuspecting users are more likely to trust the page and follow the instructions.
So how can you tell if you’ve stumbled onto a malicious site? Look for subtle clues: the CAPTCHA might be oddly worded, use a different font, or ask for a Windows command instead of a simple text entry. If the prompt says something like “Press Windows + R, paste this line, and hit Enter,” that’s a red flag. Never copy‑paste anything into a system dialog unless you’re absolutely sure of its source.
Experts recommend a few simple defenses. First, keep your operating system and security software up to date – many ClickFix variants exploit known vulnerabilities that patches can close. Second, enable web‑browser extensions that block suspicious scripts or warn about mixed‑content pages. Third, if you’re a website owner, scan your site regularly with a reputable vulnerability scanner and watch for unauthorized changes to HTML files.
For ordinary users, the safest bet is to treat any request to run a command on your computer with extreme caution. Even if the site looks genuine, a rogue CAPTCHA can turn it into a malware trap in seconds. If you’re ever in doubt, close the tab, run a full antivirus scan, and consider reporting the site to the hosting provider.
While the scale of this operation is alarming, the good news is that it’s relatively easy to mitigate. Security firms are already notifying affected businesses, and Google has begun flagging compromised URLs in search results. Until the clean‑up is complete, stay vigilant, double‑check any “CAPTCHA” that asks you to type something other than a few characters, and remember: a quick glance can save you from a costly infection.
Editorial note: Nishadil may use AI assistance for news drafting and formatting. Readers can report issues from this page, and material corrections are reviewed under our editorial standards.