Fake CAPTCHA Tricks Users Into Running Malware

TechSpot · High sophistication
Last updated September 3, 2026

Microsoft warns of a real malware campaign (“TerminalFix”) that uses fake CAPTCHA pages to convince people to open PowerShell or Command Prompt and paste attacker-provided commands. Because the user runs the command themselves, the attack can bypass many technical safeguards and can lead to deeper access into a company network.

Key findings

  • Attackers use fake CAPTCHA pages that impersonate trusted services (including Cloudflare) to instruct users to run system commands.
  • Victims are told to open PowerShell or Command Prompt and paste a command, enabling longer multi-line scripts than older “ClickFix” variants.
  • Once executed, the malware can enable a multi-stage intrusion and provide persistent proxy access into an enterprise network.
  • The campaign relies on user manipulation, not a hidden software exploit, making awareness training a key defense.
  • Microsoft recommends controls such as limiting PowerShell/Run access where possible and enabling Microsoft Defender cloud-delivered protection.

Who’s being targeted

  • Commonly targeted roles: All employees, IT administrators, Developers, Security operations, Helpdesk.
  • Affected industries: Enterprise (cross-industry).
  • Attack channels: website.
  • Impersonated: Cloudflare (or another trusted CAPTCHA/verification provider).

Awareness takeaways

  • Treat any CAPTCHA or “security check” that asks you to run PowerShell/Command Prompt/Run commands as malicious and stop immediately.
  • Coach staff that attackers may try to bypass security tools by getting users to execute code themselves.
  • Limit and monitor scripting tools (PowerShell/Run) to only the roles that truly need them, and watch for unusual command activity.
  • Emphasize enterprise impact: a single infected device can become a stepping stone to ransomware or broader compromise.

Red flags to watch for

  • A CAPTCHA asking you to open PowerShell/Command Prompt/Run dialog
  • Instructions to paste and run commands as part of a “verification” step
  • Impersonation of a trusted brand to add legitimacy
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You land on a site, see a Cloudflare-style CAPTCHA, and it says: "Verify you are human: open PowerShell and paste this command." This is a real attack called TerminalFix. The page impersonates Cloudflare, skips the normal image puzzle, and walks you step by step to open PowerShell or Command Prompt and run their code. Here’s the nasty part: because you paste it yourself, it can slip past some defenses, then quietly turn your laptop into a proxy into our network, paving the way for ransomware. Remember this rule: if any CAPTCHA or security check tells you to open PowerShell, Command Prompt, or Run and paste a command, stop and report it to IT immediately.

Similar attacks

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Fake CAPTCHA Tricks Users Into Running TerminalFix

Fake CAPTCHA Tricks Users Into Running TerminalFix

Attackers used a fake Cloudflare “verify you are human” overlay to copy a command to victims’ clipboards and trick them into pasting it into Windows Terminal/PowerShell. The command kicked off a multi-stage infection chain, including downloading payloads hidden inside PNG images, establishing…

August 31, 2026
Fake Cloudflare CAPTCHA Tricks Users Into Running Code

Fake Cloudflare CAPTCHA Tricks Users Into Running Code

A campaign dubbed “TerminalFix” uses compromised websites to display fake Cloudflare CAPTCHA checks that instruct visitors to copy and run a PowerShell command. The goal is to get a user to run attacker-provided commands themselves, which can lead to persistent access and deeper intrusion into the…

August 31, 2026
Fake reCAPTCHA “Fix” Spreads MaaS Malware

Fake reCAPTCHA “Fix” Spreads MaaS Malware

Researchers observed real campaigns using compromised WordPress sites to show fake verification/BSOD-style prompts that trick users into running a copied PowerShell command. The technique (ClickFix) was paired with MaaS tools (ErrTraffic and Cruciferra) to deliver malware while attempting to kill…

August 19, 2026
Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Fake CAPTCHA “Fix” Tricks Users Into Running Malware

Multiple real-world intrusions used a ClickFix-style lure where victims visiting compromised websites saw fake CAPTCHA prompts and were tricked into running a command themselves. Separately, attackers also abused the legitimate, signed Node.js runtime (node.exe) to run malicious JavaScript while…

September 3, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026