The fake CAPTCHA scam: why no real check asks you to press Win+R

It looks like the "I'm not a robot" box you click every week. Then it asks you to open the Run dialog and paste. That second step is the whole attack.

The fake CAPTCHA scam, often called ClickFix by security researchers, is one of the most effective tricks on the web right now. You land on a page that shows a familiar "Verify you are human" box. You tick it. Instead of pictures of traffic lights, you get instructions: press Win+R, press Ctrl+V, press Enter. Follow them and you have just run a program the page chose, with your own hands.

Security companies including Proofpoint and Microsoft have documented these campaigns spreading through compromised sites, fake download pages and search ads. They work because every step feels routine. Here is how it works and how to stay out of it.

How the fake CAPTCHA scam works

  1. The bait. You reach the page from a search result, an ad, a hacked site or a link in a message. It might pretend to be a document, a video, a software download or a site behind a "security check".
  2. The fake check. A box that looks like reCAPTCHA or a Cloudflare check appears. When you click it, the page silently copies a command to your clipboard.
  3. The instructions. The page tells you to "complete verification" with a short key sequence: open the Run dialog with Win+R, paste with Ctrl+V, and press Enter. Some versions say "press the Windows key" or show the keys as pictures.
  4. The payload. The pasted command, usually PowerShell or mshta, downloads and runs malware. Commonly that is an information stealer that takes saved passwords, browser cookies and crypto wallets.

The pasted text is often padded so the visible part of the Run box shows something reassuring, like I am not a robot - reCAPTCHA Verification ID: 4821, while the real command sits off to the left.

The Mac version

On a Mac, the page asks you to press Command+Space, type "Terminal", paste and press Return. The command typically starts with curl or bash and downloads a stealer built for macOS. The rule is the same: no website verification needs a Terminal.

The one rule that stops it

A real CAPTCHA happens entirely inside the web page. It might ask you to tick a box, pick pictures or wait a moment. It will never ask you to:

  • Press Win+R, or open the Run dialog
  • Open Terminal, PowerShell or Command Prompt
  • Paste anything anywhere outside the page
  • Press keys "to complete verification"

If a page asks for any of these, close the tab. That's it. You don't need to judge the design, the address or the wording: the request itself is the proof.

Why it works so well

  • It borrows trust. People complete CAPTCHAs constantly and have learned to follow them without thinking.
  • It skips your defences. The browser didn't download anything, so download warnings never fire. You ran the command yourself.
  • It is cheap to deploy. The fake check is a few lines of code that can be dropped into a hacked site or a page built in minutes, including on AI app builders' free hosting.

If you already ran it

Act quickly. The malware usually starts copying data right away.

  1. Disconnect the computer from the internet (turn off Wi-Fi or unplug the cable).
  2. From a different, clean device, change the passwords for your email, bank and any accounts saved in your browser. Start with email, because it can reset everything else.
  3. Sign out of all sessions where your accounts offer it, since stolen cookies can keep a thief signed in even after a password change.
  4. Move crypto to a new wallet from a clean device if you have any on that computer.
  5. Run a full scan with up-to-date security software, or ask a professional to check or reinstall the computer.
  6. Watch your accounts for logins and payments you don't recognise.

If it was a work computer, tell your IT or security team straight away. They would much rather hear early.

Report the page

Reporting helps get the page blocked for everyone. Our guide on how to report a phishing website lists where to send it.

How Kitsuvo handles fake CAPTCHAs

Kitsuvo, our no-AI web browser, reads every page you open on your own computer. When a page combines verification wording with instructions to open the Run dialog or Terminal and paste, it treats that as impersonation and shows a warning screen with Go back as the first choice. It's one of a small set of high-precision rules, alongside look-alike sign-in pages, described in how to spot phishing sites built with AI builders.

Questions people ask

Is it safe to press Win+R for a CAPTCHA?

No. No legitimate CAPTCHA or website check asks you to open the Run dialog. A page that does is trying to make you run a command it has copied to your clipboard. Close it.

What is ClickFix?

ClickFix is the name security researchers use for attacks that show a fake error or fake CAPTCHA and tell you to paste and run a command to "fix" it. The command installs malware.

I clicked the fake CAPTCHA but did not paste anything. Am I infected?

Clicking the box only copies text to your clipboard. If you did not paste it into the Run dialog, Terminal or PowerShell and press Enter, the command did not run. Close the page and copy something harmless to clear your clipboard.