Fake CAPTCHA ClickFix malware attack targeting a Windows PC

Fake CAPTCHA Scams Use ClickFix to Install Malware on Windows PCs

Category: Cybersecurity

CAPTCHA checks are meant to stop bots. They are not supposed to make you run commands on your own computer. That is exactly what fake CAPTCHA scams are trying to do. A page may tell you to press Windows + R, paste something, and hit Enter. In seconds, a normal-looking verification screen can become a malware attack. Here is how ClickFix works, what to watch for, and what to do next.

Why Fake CAPTCHAs Fool People

Most of us barely think about CAPTCHA checks anymore. You check a box, pick out a few traffic lights, solve a small puzzle, and move along.

That routine is part of the problem.

Cybercriminals know people are used to following CAPTCHA instructions without thinking too hard about them. A technique called ClickFix takes advantage of that trust. Instead of quietly breaking into Windows on its own, the attack tries to convince you to do part of the work.

The page may look like a security check. It may claim there is a browser problem or say one more step is needed to prove you are human. Then the instructions take an unexpected turn.

Microsoft describes ClickFix social engineering as a technique that tricks people into copying, pasting, and running malicious commands. Microsoft has seen these attacks spread through phishing emails, malicious advertising, compromised websites, and other online lures.

That is what makes ClickFix easy to miss at first.

There may be no suspicious program asking to download. No strange attachment. No giant warning saying malware is about to run.

Instead, the criminal tries to make the dangerous action look like normal verification.

A CAPTCHA should not need that kind of access to your computer.

How ClickFix Gets You to Run Code

A ClickFix attack can start with an ordinary-looking webpage.

Maybe the site says you need to prove you are human. Maybe it claims your browser failed a check. Another version might say a document cannot open until you complete a quick verification step.

Then come the instructions.

A common sequence looks like this:

  • Press Windows + R.
  • Press Ctrl + V.
  • Press Enter.

To someone who does not work with Windows commands very often, those steps may look odd but harmless. They are not.

Windows + R opens the Run dialog. Ctrl + V pastes whatever is stored in the Windows clipboard. Pressing Enter tells Windows to act on what was pasted.

Here is the clever part. You may not remember copying anything.

Microsoft says ClickFix attacks can use clipboard hijacking to put a malicious command into the clipboard. The fake CAPTCHA then tells you exactly how to paste and execute it. Microsoft’s technical description of the ClickFix attack process explains how this can happen.

From your point of view, you just completed a weird CAPTCHA.

Windows sees something else entirely. It sees a command entered by the person using the computer.

That is the trick.

The attacker controls the instructions, but the victim performs the final step.

Why Windows Run Can Be Misused

Windows Run is not dangerous by itself.

Pressing Windows + R simply opens a legitimate Windows feature. Run can launch programs, open folders, reach system utilities, and start commands. Plenty of normal Windows tasks use it.

Its flexibility is exactly why criminals want access to it.

People have been warned for years not to open strange .exe files or suspicious email attachments. That advice has helped. An unfamiliar program often looks risky before you even click it.

A line of pasted text feels different.

It looks like text. Maybe a messy one. Maybe something full of symbols, web addresses, or random characters.

But text entered into a command tool can tell Windows to do real things.

A malicious command may start PowerShell, run a script, contact a server, download another file, or launch software already built into Windows. Sometimes several actions happen quickly enough that the person at the keyboard barely sees them.

Proofpoint has documented ClickFix attacks using Windows Run and PowerShell as part of malware delivery campaigns.

So the shortcut is not the threat.

Windows Run is not dangerous. The unknown command is.

That difference matters. There is no reason to fear Windows + R during normal use. There is plenty of reason to stop when an unfamiliar website tells you what to paste into it.

What the Malware May Be After

Running the command may only start the infection.

ClickFix is not one specific virus. It is a delivery method. Different criminal groups can use the same basic trick to install very different types of malware.

That means the result can vary.

Some campaigns have delivered information-stealing malware. Others have installed remote-access tools or software that helps attackers maintain control of an infected computer.

Depending on the malware involved, criminals may go after:

  • Saved browser passwords and autofill data.
  • Browser cookies and active login sessions.
  • Email and cloud account credentials.
  • Business application logins.
  • Cryptocurrency wallet information.
  • Personal or financial documents.
  • Credentials stored by other applications.
  • Information that helps unlock additional accounts.

Microsoft’s broader ClickFix threat analysis describes campaigns connected with information theft, credential collection, and other malicious activity.

This is also why a computer may look perfectly normal afterward.

Information-stealing malware does not always want your attention. Quite the opposite.

A criminal who wants passwords, browser data, or account sessions may benefit from keeping the computer quiet. No flashing warning. No obvious crash. Maybe nothing strange at all.

That silence can create false confidence.

If you ran a suspicious command and nothing happened on the screen, that does not mean nothing happened inside the computer.

How to Recognize a Fake CAPTCHA

You do not need to learn every version of ClickFix.

That would be nearly impossible anyway. Scams change, websites get redesigned, and attackers constantly test new ways to make their instructions look believable.

A simpler rule works better.

Look at what the CAPTCHA is asking you to do.

A normal CAPTCHA might ask you to:

  • Check a box.
  • Choose matching pictures.
  • Complete a small puzzle.
  • Wait while verification takes place.
  • Try the challenge again.

Those actions stay in the website or browser.

Google describes reCAPTCHA as a system designed to help websites separate legitimate users from abusive automated traffic. Its documentation on how reCAPTCHA works shows verification taking place through the website or application and its supporting systems.

That is very different from telling you to start using Windows tools.

Be suspicious if a supposed CAPTCHA tells you to open Windows Run, PowerShell, Command Prompt, or Windows Terminal. The same goes for instructions asking you to run a script, install a special verification program, disable security software, or give someone remote access.

Those requests have nothing to do with proving you are human.

There is an easy line to remember:

A CAPTCHA belongs in the browser. Windows commands do not.

If the verification suddenly crosses that line, stop.

What to Do If You Ran the Command

Maybe you already followed the instructions.

You pressed Windows + R. You pasted whatever was waiting in the clipboard. Then you hit Enter.

Nothing obvious happened.

Do not assume that means you are fine.

If you think malware may have been executed, disconnect the computer from the internet while you begin checking it. That can help interrupt some communication between the infected computer and an outside server.

Then work through the problem methodically:

  1. Run a full scan with Microsoft Defender Antivirus or another reputable security program.
  2. Make sure your antivirus definitions are current.
  3. Consider running Microsoft Defender Offline.
  4. Install current Windows and browser security updates.
  5. Check recently installed programs.
  6. Look for browser extensions you do not recognize.
  7. Review startup applications for anything unfamiliar.
  8. Avoid entering important passwords on the computer until you have checked it carefully.

Microsoft explains that Microsoft Defender Offline restarts the computer and scans outside the normal Windows environment. That can make it harder for certain malware to hide while the scan is running.

A clean scan is good news, but keep the limits in mind.

It cannot travel backward in time.

If malware already collected a password, cookie, login session, or document before being removed, cleaning the computer does not retrieve that information from whoever received it.

That is why the next step matters just as much.

Protect Your Accounts Afterward

Once you have dealt with the computer itself, turn your attention to your accounts.

Use a different device that you trust.

Start with your main email account. Email is especially important because password reset messages for many other services end up there. If someone controls your email, they may have a path into much more.

Change passwords that may have been exposed. Check recent sign-ins. Review recovery email addresses and phone numbers. Sign out of sessions you do not recognize.

Then move through other important accounts, including banking, cloud storage, shopping, social media, and business services.

The Federal Trade Commission recommends changing passwords and using two-factor authentication after a suspected malware infection. Its consumer advice on detecting and removing malware also warns against entering sensitive information on a device you believe may still be infected.

For a work computer, the stakes can climb quickly.

An infected system might contain customer records, accounting information, cloud access, saved business sessions, internal documents, or administrator credentials.

If sensitive company data may have been exposed, involve whoever handles IT or cybersecurity for the business. Small organizations should not assume they are too minor to attract attention. Automated attacks do not care how many employees you have.

One employee following the wrong three instructions can be enough.

JENI® and Routine PC Maintenance

Good computer maintenance cannot prevent every cyberattack, but it still plays an important role in keeping a Windows PC manageable.

JENI® helps Windows users handle routine PC maintenance through a straightforward interface built for everyday users. The idea is simple: common maintenance should not require someone to become a computer technician.

JENI® does not replace antivirus software, Windows security updates, backups, account protection, or smart browsing choices. Those tools and practices solve different problems.

A clean, well-maintained computer can still become infected if someone runs a malicious command.

The reverse is also true. Antivirus software cannot make a suspicious command trustworthy simply because a website convinced you to execute it.

Better protection comes from layers.

Keep Windows updated. Use reputable security software. Back up important files. Maintain the computer. Protect your accounts.

And when a webpage suddenly asks you to jump out of the browser and start typing commands into Windows, stop and ask why.

That small pause can matter a lot.

The ClickFix Warning Worth Remembering

Fake CAPTCHA scams work because the setup feels familiar.

You have seen verification pages before. Probably hundreds of them. The logo may look right. The page may be clean and polished. The instructions might even sound technical enough to feel official.

Then comes the request that gives the scam away.

Microsoft’s research into the ClickFix social engineering technique shows how attackers depend on the user to perform key actions that help execute the malicious command.

That also gives users a chance to break the chain.

Remember this:

If a website tells you to press Windows + R, paste something, and press Enter, do not do it.

Close the page.

The warning goes beyond one keyboard shortcut. Be cautious anytime a normal website suddenly asks you to open command tools, run scripts, disable security settings, or install software just to prove you are human.

A CAPTCHA does not need control over Windows to verify that there is a person sitting at the keyboard.

You do not need to understand PowerShell or decode a strange command to know when something feels wrong.

Sometimes that is enough to stop the attack.

Frequently Asked Questions

What is a fake CAPTCHA scam?

A fake CAPTCHA scam copies the look of a real human-verification check but gives you instructions that can put your computer at risk. Some versions tell Windows users to open Run, paste clipboard contents, and execute a malicious command.

What is a ClickFix attack?

ClickFix is a social engineering technique that tricks people into running malicious commands themselves. The instructions may be disguised as a CAPTCHA, browser error, document problem, security check, or another technical-looking task.

Is pressing Windows + R dangerous?

No. Windows + R simply opens the legitimate Windows Run dialog. The danger starts when you paste or type an unknown command into Run and execute it.

Can pasted text really install malware?

Yes. Text entered into Windows Run, PowerShell, Command Prompt, or another command interface can contain instructions that launch scripts, download files, start programs, or connect the computer to outside systems.

What should I do if I already ran it?

Treat the computer as potentially compromised and avoid entering sensitive information until you have checked it. Run updated security scans, consider Microsoft Defender Offline, protect important accounts from another trusted device, and review those accounts for unfamiliar activity.

Related Articles

How Fake Windows Updates Spread ClickFix Malware

See how fake Windows Update screens use ClickFix tactics to trick people into running malicious commands and installing malware on their computers.

How Google Meet ClickFix Attacks Spread Malware

Learn how fake Google Meet pages can use ClickFix tricks to deliver remote-access malware and turn a familiar online service into an attack.

How Social Engineering Tricks Computer Users

Learn how social engineering exploits trust, urgency, and familiar routines to persuade people to reveal information or perform risky computer actions.

What to Do If Your Computer Has Been Hacked

Follow practical steps to check a compromised computer for malware, protect important accounts, secure personal data, and reduce further damage.

Published on July 28, 2026 at 3:58 PM by:

Geoffrey has decades of hands-on experience in IT, software development, and cybersecurity, bringing expert technical insight to every article. He holds two IT bachelor’s degrees, a business degree, and a master’s degree in Cybersecurity and Information Assurance.