Microsoft is warning Windows users about a growing cyber threat that hides behind something that looks completely harmless: a CAPTCHA test. Hackers use fake verification pages to trick victims into following instructions that can secretly run malicious commands on their computers, turning a routine security check into a dangerous trap. The attacks are becoming more convincing, making it harder for users to spot the warning signs. Read on to learn how these fake CAPTCHA tests work and what Microsoft says users should watch for.
How the trap unfolds
When navigating the web, encountering a CAPTCHA — a short test asking you to check a box or identify images — has become second nature. Attackers behind this newly identified “ClickFix” campaign exploit that muscle memory.
It all begins when a user visits a compromised website. Instead of a normal webpage, a fraudulent verification or repair window pops up, mimicking a standard security check. But unlike legitimate CAPTCHA services that process your actions safely inside your web browser, this malicious lure asks you to step outside the browser altogether.
The prompt instructs the victim to copy a snippet of text, open the Windows Run dialog box (by pressing Windows Key + R), paste the copied content, and press Enter. To an everyday user, it might look like a quick system fix or routine identity verification. But in reality, it hands the key to the computer directly to the attacker.
How it bypasses your antivirus software
What makes this campaign particularly dangerous is how it tricks both users and traditional antivirus software. Normally, security tools monitor the internet for suspicious file downloads. The ClickFix technique completely bypasses this guardrail through a clever two-step trick:
- Pre-loading the trap: Before you even interact with the fake CAPTCHA, the compromised site secretly downloads a heavy malicious script into your browser’s temporary storage (cache). To mask its true identity, the file is disguised as a harmless image (.PNG).
- Short and silent commands: Because the malicious payload is already sitting inside your browser’s cache, the command you paste into the Run box doesn’t need to download anything new. It simply runs a quick search on your hard drive, finds that hidden “image” file, renames it into a script (.vbs), and launches it in the background — all without displaying any pop-ups or error messages.
By keeping the pasted command brief, attackers easily bypass character limits in Windows while keeping traditional download scanners in the dark.
What happens behind the scenes
Once launched, the script quietly digs deeper into the infected system. It uses built-in administrative tools like PowerShell and Windows Management Instrumentation (WMI) to gather detailed system information and fetch additional malicious files.
From there, the malware sets up a multi-stage infection process:
- Memory infiltration: It loads harmful scripts directly into your computer’s temporary memory rather than saving them to the hard drive, making detection even harder.
- Data theft: The ultimate goal of this covert operation is to target and steal stored web browser passwords, personal credentials, and sensitive device data.
- Long-term control: To ensure attackers don’t lose access if you reboot your PC, the malware secretly modifies system settings, extracts hidden background tools, and schedules automated tasks to keep running silently in the background.
How to stay protected
Microsoft emphasizes that staying safe comes down to a combination of smart security software and user vigilance.
Built-in protections like Microsoft Defender SmartScreen, Defender for Office 365, and Defender for Endpoint offer layered defense by blocking known malicious sites and flagging suspicious “ClickFix” behavior. Security systems categorize and detect these active threats under names like Trojan:Win32/ClickFix and Trojan:Win32/TermFix. IT administrators are advised to turn on cloud-delivered protection, web protection, network monitoring, and script-logging to spot abnormal command activity.
However, the primary line of defense relies on knowing what a real security test looks like.
The golden rule of web safety
No legitimate CAPTCHA, browser verification service, or official IT support team will ever instruct you to copy and paste commands into your Windows Run dialog, Command Prompt, PowerShell, or Terminal. Any request asking you to do so should immediately be treated as a malicious attack.
Source:
gbhackers
