Fake CAPTCHA Scam: Why “Verify You’re Human” Can Install Malware
A CAPTCHA normally asks you to prove that you are human by selecting images, checking a box, or completing a simple challenge.
But scammers are now using fake CAPTCHA pages to trick people into running malicious commands on their own computers.
A major warning sign is a “Verify you’re human” page that asks you to press Windows + R, paste something, and press Enter.
A real CAPTCHA should not require you to run commands on your computer.
1. What Is a Fake CAPTCHA Scam?
A fake CAPTCHA scam copies the appearance of a legitimate human-verification page.
The FTC has warned about fake CAPTCHA pages that tell users to press Windows + R, Ctrl + V, and Enter, which can run hidden malware
Instead of simply verifying that you are human, the page may instruct you to:
- Press Windows + R
- Press Ctrl + V
- Paste a command
- Open PowerShell, Terminal, or Command Prompt
- Press Enter to “complete verification”
These instructions can cause malicious software or scripts to run on your computer.
2. Why Is Windows + R a Warning Sign?
Windows + R opens the Windows Run dialog.
The Run box itself is legitimate, but a website should not need you to use it just to prove that you are human.
If an unfamiliar website tells you to copy and run a command, stop.
Microsoft has also documented ClickFix attacks that use fake CAPTCHA or warning pages to trick users into running malicious commands.
The command may download or execute malware without making its real purpose obvious.
3. What Can the Malware Do?
Depending on the malware involved, attackers may try to steal:
- Email passwords
- Browser-stored credentials
- Financial information
- Cryptocurrency wallet information
- Personal files
- Account login details
Malware may also give attackers additional access to the computer.
4. How to Recognize a Fake CAPTCHA
Be suspicious if a CAPTCHA:
- Tells you to open the Windows Run box
- Tells you to paste a command
- Requests PowerShell or Command Prompt
- Asks you to download a file
- Claims unusual computer actions are required for verification
- Appears immediately after visiting a suspicious link or unfamiliar website
A normal CAPTCHA should stay primarily inside the browser.
5. What If You See One but Haven't Run the Command?
If you have not executed anything, do not follow the instructions.
Close the page.
Do not paste the copied text into:
- Run
- PowerShell
- Command Prompt
- Terminal
If you arrived through an unexpected email, message, advertisement, or suspicious link, do not reopen it.
If you are unsure about a link, follow our guide on what to do with a suspicious link before clicking it again.
6. What If You Already Ran the Command?
Treat the computer as potentially compromised.
First, disconnect it from the internet if you suspect malware may be running.
Then use reputable, updated security software to perform a thorough scan.
If malware is detected or you still suspect an infection, follow our step-by-step guide to remove malware from a Windows PC.
Do not continue entering passwords, banking details, or other sensitive information on the affected computer until you have checked it.
7. Protect Your Important Accounts
If you entered passwords after running a suspicious command, use a different trusted device to secure important accounts.
Prioritize:
- Your email account
- Banking and payment accounts
- Password manager
- Social media
- Shopping and other important accounts
Change affected passwords and enable multi-factor authentication where available.
8. Check for Suspicious Account Activity
Review important accounts for:
- Unknown logins
- Password-reset attempts
- Changed recovery information
- Unknown devices
- Unexpected transactions
- Messages you did not send
Contact your bank or payment provider promptly if you notice unauthorized financial activity.
9. How to Avoid Fake CAPTCHA Scams
Remember one simple rule:
A website should not require you to run a Windows command just to prove you are human.
Also:
- Avoid unexpected links.
- Take browser warnings seriously.
- Keep Windows and your browser updated.
- Use reputable security software.
- Never run commands you do not understand.
- Verify suspicious requests independently.
Quick Safety Checklist
If a “Verify you’re human” page appears:
- Does it ask for Windows + R?
- Does it ask you to paste a command?
- Does it ask for PowerShell or Command Prompt?
- Did you reach it through a suspicious link?
- Is it asking you to do something outside the browser?
If yes, stop and close the page.
Final Thoughts
Fake CAPTCHA scams are dangerous because they make the victim perform the action that can start the infection.
The CAPTCHA may look convincing, but the instruction is the giveaway.
If a website tells you to press Windows + R, paste a command, and press Enter to verify that you are human, do not do it.
If you already followed those instructions, disconnect the affected computer, scan it with trusted security software, and secure important accounts from another trusted device.
Guide note: Scam techniques change over time. This article reflects security guidance and reported fake CAPTCHA tactics available in August 2026.

Comments
Post a Comment