Fake CAPTCHA Scams: 7 Warning Signs That a “Prove You’re Human” Page Is Dangerous
Scammers are disguising malicious instructions as routine human verification. One rule can stop the attack: a CAPTCHA should never ask you to run a command.
CAPTCHA screens have become an ordinary part of using the internet. We check a box, identify a traffic light, wait for a browser check, and continue to the page we wanted.
That familiarity is now being exploited.
Fake CAPTCHA scams can imitate recognizable verification tools while instructing people to open Windows Run, PowerShell, Command Prompt, or macOS Terminal. The person is told to paste something and press Enter to “prove” they are human—but those steps can execute a malicious command.
Microsoft calls this social-engineering technique ClickFix. Microsoft reported that CAPTCHA-gated phishing volume more than doubled in March 2026, reaching approximately 11.9 million attacks within its observed email data.
If You Read Only One Thing
A real CAPTCHA verifies you inside the webpage. It should never ask you to open Windows Run, PowerShell, Command Prompt, or Terminal; paste a command; install software; or disable a security feature.
You do not need to determine whether the logo, website, or verification box looks authentic. The requested behavior is the clearest warning.
Your Action Steps
If a “Prove you’re human” page asks you to perform unusual computer steps:
Stop immediately.
Do not use the requested keyboard shortcuts.
Do not paste anything the website placed on your clipboard.
Close the browser tab.
Return to the website independently if you still need to use it.
If you already executed a command, disconnect the device from the internet and follow the response steps later in this article.
What Is a Fake CAPTCHA Scam?
A legitimate CAPTCHA may ask you to check a box, identify an image, solve a simple puzzle, or wait while the browser checks your connection.
A ClickFix-style CAPTCHA does something fundamentally different: it asks you to operate your computer.
The attack may begin through an unexpected email, a malicious advertisement, an attachment, a search result, or a compromised website. The resulting page may impersonate Google reCAPTCHA, Cloudflare Turnstile, Microsoft, a government agency, a travel company, or another recognizable organization.
After the person clicks the verification box, the page may secretly place a malicious command on the computer’s clipboard. It then provides instructions that appear simple:
Press Windows + R.
Press Ctrl + V.
Press Enter.
Following those instructions can download malware, steal information, or give an attacker remote access to the device. Because the person initiates the command, the attack may bypass protections that would normally block an automatic download.
Seven Warning Signs of a Fake CAPTCHA
1. The Verification Process Leaves Your Browser
A CAPTCHA should be completed inside the webpage.
If the instructions send you into Windows, macOS, a command window, or another part of the operating system, stop. A website does not need you to operate your computer to determine whether you are human.
2. It Tells You to Press Windows + R
Windows + R opens the Windows Run dialog. It allows commands and programs to be launched directly.
A legitimate human-verification tool has no reason to ask you to open it.
Be equally suspicious of instructions involving:
PowerShell
Command Prompt
Windows Terminal
macOS Terminal
“Alternate verification” through a system window
The language may sound technical and official. The request is still dangerous.
3. It Tells You to Paste Something You Cannot See or Understand
Some fake CAPTCHA pages copy a command to the clipboard when you click the verification box. The page then tells you to press Ctrl + V or Command + V.
You may never see what was copied before it is pasted.
Never paste website-provided text into Windows Run, PowerShell, Command Prompt, or Terminal unless you independently understand and trust the exact command. For ordinary internet use, a website should not ask you to do this at all.
4. It Tells You to Press Enter to Complete Verification
Pressing Enter may look like the final step in a harmless process. In a ClickFix attack, it can execute the command that was just pasted.
The sequence is intentionally simple because each step feels small:
Open a window.
Paste.
Press Enter.
Together, those actions can initiate a malware download.
5. It Requires a Download, Extension, Password, or Security Change
Human verification should not require you to:
Download a file
Install an application or browser extension
Enter your computer’s administrator password
Disable antivirus protection
Remove a file from quarantine
Change browser security settings
Grant remote access
Open an unfamiliar file
Microsoft has documented ClickFix-style attacks against both Windows and macOS. Mac users may be told to paste commands into Terminal or enter a system password. The resulting malware can target browser passwords, account credentials, cryptocurrency wallets, and other sensitive information.
6. It Appears After an Unexpected Email, Advertisement, Attachment, or Redirect
Be especially cautious when the CAPTCHA appears after you:
Click a link in an unexpected email
Open a PDF or HTML attachment
Select a sponsored search result
Click an online advertisement
Attempt to stream questionable content
Are redirected away from the page you intended to visit
Encounter an unexpected account or document error
Microsoft documented a Booking.com impersonation campaign in which targets were shown a fake CAPTCHA over a convincing imitation of the company’s website. The CAPTCHA instructed them to open Windows Run and execute a command capable of delivering credential-stealing malware.
The page’s polished appearance did not make its instructions safe.
7. The Page’s Instructions Matter More Than Its Branding
A fake CAPTCHA may use familiar logos, colors, background images, and security language. It can closely resemble a legitimate verification product.
It may even appear on a real website that has been compromised.
Do not rely exclusively on whether the page “looks right.” Instead, evaluate what it asks you to do.
If the page asks you to operate your computer instead of completing a simple browser-based check, close it.
Why These Scams Work
ClickFix attacks exploit a normal human tendency: when we encounter a small technical problem, we want to solve it and continue with what we were doing.
The fake CAPTCHA creates several layers of false reassurance:
CAPTCHA screens are familiar.
Verification feels security-related.
The instructions appear simple.
Recognizable branding creates trust.
Each individual action seems minor.
The person believes they are fixing a problem rather than launching a program.
The safest response is not to become more technically sophisticated than the attacker. It is to maintain a clear boundary:
A webpage should not instruct you to execute computer commands.
What If You Already Followed the Instructions?
Your next step depends on how far you went.
If You Clicked the CAPTCHA but Did Not Paste or Run Anything
Close the page. Copy a piece of harmless text to replace anything the website may have placed on your clipboard.
Do not return through the same email, advertisement, attachment, or link.
If You Pasted the Command but Did Not Press Enter
Close the Run, PowerShell, Command Prompt, or Terminal window without executing the command. Close the browser page and replace the clipboard contents with harmless text.
If You Executed the Command
Take the situation seriously without panicking:
Disconnect the computer from Wi-Fi or wired internet.
Stop using that device for email, banking, shopping, or password changes.
If it is a work-managed device, contact your employer’s IT or security team immediately.
Run a complete scan using trusted security software.
Seek qualified technical assistance if you are uncertain whether the device is clean.
From a different, trusted device, change critical credentials—beginning with email, your password manager, financial accounts, and other high-value services.
Review active sessions and recent account activity.
Enable or review multifactor authentication.
Monitor financial accounts for unauthorized transactions.
Information-stealing malware can target saved browser passwords, cookies, financial information, and account credentials. Merely deleting the browser history is not an adequate response after executing an unknown command.
The Rule to Remember
You do not need to memorize every fake CAPTCHA design or learn how to read computer commands.
Remember the boundary:
Human verification belongs inside the webpage. The moment it asks you to open a system tool, paste a command, install something, or change your security settings, stop.
Resources Outside Haven Smith & Company
Think Before You Click(Fix): Analyzing the ClickFix Social Engineering Technique — Microsoft’s detailed explanation of how ClickFix attacks reach people and trick them into executing commands.
Email Threat Landscape: Q1 2026 Trends and Insights — Microsoft’s current reporting on CAPTCHA-gated phishing.
Booking.com Impersonation Campaign Delivers Credential-Stealing Malware — A documented example of fake CAPTCHA instructions being used to deliver malware.
Infostealers Without Borders: macOS, Python Stealers, and Platform Abuse — Information about ClickFix-style attacks affecting Mac users.
ClickFix Social Engineering Technique Floods the Threat Landscape — Proofpoint research on fake CAPTCHA campaigns and the malware they deliver.
Haven Smith & Company Resources
Free Digital Life Management resources:
https://www.havensmith.company/start-hereDigital Safety Course:
https://www.havensmith.company/digital-safetyDigital Life Management Course Bundle:
https://www.havensmith.company/bundleBook a free 15-minute consultation:
https://www.havensmith.company/free-consultation
Haven Smith & Company provides practical education, tools, and guidance to help individuals, families, professionals, businesses, and institutions organize, protect, and prepare their digital lives with confidence.