Fake CAPTCHA Pop-ups Trick Users Into Running Commands

TechSpot · Medium sophistication
Last updated September 15, 2026

Researchers warn that “ClickFix” attacks are spreading on both Windows and Mac by showing fake pop-ups over trusted websites and instructing people to copy/paste and run hidden commands. Attackers are also compromising legitimate websites so the scam appears on pages users already trust, increasing the chance they’ll follow the instructions and install malware.

How the Attack Works

ClickFix attacks begin with a pop-up displayed over a trusted web page that delivers urgent, step-by-step instructions. The pop-up is often disguised as a CAPTCHA or security verification check, a format most users recognize and rarely question. Instead of simply clicking a checkbox, though, the victim is instructed to copy a command, paste it into the Windows Run prompt or Mac command line, and execute it. That single action can hand attackers a foothold on the device, all without the user ever downloading a visible file.

Why It Succeeds

The technique works because it borrows the credibility of everyday web friction. CAPTCHA prompts are so common that people follow them almost automatically. Attackers have also started compromising legitimate websites so the fake overlay appears on pages users already trust and visit regularly. This removes one of the biggest red flags people rely on, the idea that a shady-looking site is the main danger. When the compromised site is one an employee visits daily for work, the instructions carry an unearned sense of legitimacy.

What to Watch For

  • A CAPTCHA or web verification prompt should never ask a user to open a Run box or Terminal and paste in a command.
  • Overlays that create urgency and push manual copy/paste execution outside the browser are a strong warning sign.
  • Prompts appearing on a site that is normally trusted do not guarantee the site itself is safe, since it may have been compromised.
  • Reports show victims flooding Reddit with requests for help, suggesting this technique is already succeeding at scale across both Windows and Mac users.

Building Resistance

The clearest defense is training staff that no legitimate CAPTCHA or security check ever requires copying and pasting a command into a command line. Employees should be encouraged to report unusual pop-ups or overlays to IT or security rather than following the instructions themselves, even on sites they use regularly. Organizations can also consider technical controls, such as restricting access to the Run prompt or command line for user groups that do not need it, as an added layer beyond awareness training. Given that fake CAPTCHA prompts have reportedly appeared in other contexts as well, ongoing awareness about this pattern, not just a one-time warning, is important for keeping pace with how the technique keeps showing up in new places.

Key findings

  • ClickFix uses pop-ups over trusted pages to pressure users into following step-by-step instructions.
  • Attackers “weaponized CAPTCHA overlay windows” and instruct victims to “copy, paste and execute a covert command” in Windows or Mac command line.
  • Victims are reportedly “flooding Reddit with requests for help,” indicating the technique is working at scale.
  • Attackers are “compromising legitimate websites” so the malicious prompt appears on sites users already visit.
  • Some state-sponsored/APT actors have started using ClickFix; fake CAPTCHA windows are also appearing in places like Google Sheets and smart contracts.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT support/helpdesk, Security awareness trainees.
  • Attack channels: website.
  • Impersonated: CAPTCHA / website security verification prompt.

Red flags to watch for

  • A CAPTCHA or web prompt should not require running commands in Terminal/Run
  • Urgent/instructional overlay that pushes manual copy/paste execution
  • Appears on an otherwise trusted site due to possible website compromise
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a ClickFix attack?

ClickFix is a social engineering technique where a pop-up appears over a trusted web page and pressures the user to copy, paste and execute a command in the Windows or Mac command line, often disguised as a CAPTCHA check.

Can ClickFix attacks appear on legitimate websites?

Yes, attackers are compromising legitimate websites so the malicious prompt appears on pages users already visit and trust, making the scam more convincing.

How can organizations reduce the risk of ClickFix?

Beyond training staff never to run copy/pasted commands from pop-ups, some organizations limit access to command line or Run prompt features for user groups that do not need them.

Why is this attack technique concerning?

Reports indicate victims are flooding Reddit with requests for help, and some state-sponsored actors have started using ClickFix, suggesting the technique works at scale and is spreading beyond a single platform or actor type.

Read the video transcript

You’re on a site you trust, and suddenly a CAPTCHA pops up: “Please verify you are human. Follow the steps below to continue.” This is a ClickFix attack. Cybercriminals have weaponized CAPTCHA overlay windows, telling you to copy, paste, and run a secret command in Windows Run or Mac Terminal. The twist? They’re compromising legitimate websites, so this fake security check can appear on pages you visit every day, people are flooding Reddit asking what they just ran. A real CAPTCHA never needs your Run box or Terminal. If any web pop-up tells you to run a command, stop, close it, and report it to IT immediately.

Similar attacks

Fake Download Sites Push Malware Installers

Fake Download Sites Push Malware Installers

Microsoft reports an active campaign where attackers set up counterfeit software download pages that mimic well-known brands and trick users into installing malware. Victims visit a look-alike vendor site, click “Download now,” then run a bundled installer that drops persistent malware and connects…

September 2, 2026
Fake CAPTCHA ‘ClickFix’ Drops Cruciferra Malware

Fake CAPTCHA ‘ClickFix’ Drops Cruciferra Malware

A real malware campaign used compromised websites to show fake CAPTCHA/verification pages that tricked people into copying and running a PowerShell command themselves. That manual “copy/paste” step helped the attackers bypass normal download defenses and install the Cruciferra loader, which then…

August 25, 2026
BengalSEO: Search Lures to Malware & Scam Calls

BengalSEO: Search Lures to Malware & Scam Calls

Investigators described a real, long-running SEO poisoning operation (“BengalSEO”) that manipulates search results to push victims to fake support and activation pages. The pages impersonate well-known consumer brands, then route visitors through redirects and CAPTCHA checks to either download…

September 1, 2026
Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Fake Minecraft Clients Push WeedHack Malware

Fake Minecraft Clients Push WeedHack Malware

Attackers are tricking Minecraft players into downloading malware by impersonating popular Minecraft clients and resellers in Google search results. Even after the campaign’s command-and-control infrastructure was taken down, the operation continued by shifting distribution to common file-hosting…

August 25, 2026
Spy Groups Phish Victims Into Chrome Exploit Kit

Spy Groups Phish Victims Into Chrome Exploit Kit

Researchers reported four separate espionage groups using the same “BlueMoon” exploit kit within days, targeting organizations in the US and Southeast Asia. The attacks began with phishing emails that lured recipients to attacker-controlled websites, where Chrome and Windows vulnerabilities were…

September 10, 2026