Fake CAPTCHA Tricks Users Into Running Run Command

Infosecurity Magazine · High sophistication
Last updated October 7, 2026

Microsoft observed a ClickFix campaign where compromised websites show a fake CAPTCHA that tricks people into opening Windows Run and executing a pasted command. The attack hides a VBScript payload in the browser cache (disguised as an image) so the device already has the file locally when the victim runs the command, helping the malware evade simple download-based detection and bypass Run character limits.

How the Attack Worked

This campaign used a ClickFix-style fake verification step to trick visitors on compromised websites. Instead of a normal CAPTCHA check, a pop-up instructed users to open Windows Run, paste clipboard contents, and press Enter. That single action triggered a command that searched cached browser files for a VBScript payload disguised as an image, matched it by file size, copied it as a .vbs file, and executed it with wscript.exe.

Once running, the VBScript collected host details through WMI, fetched and ran a PowerShell script with execution policy bypassed, and later injected code into timeout.exe. Persistence was set up through a scheduled task that ran a Python payload via pythonw.exe after unpacking Python with tar.exe. Microsoft Defender Antivirus detects this behavior as Trojan:Win32/ClickFix and Trojan:Win32/TermFix.

Why It Succeeded

The attack succeeded by exploiting a gap between what users expect from web verification and what it actually asked them to do. People are used to clicking checkboxes or solving puzzles for CAPTCHAs, not opening system dialogs and running commands. Hiding the payload in the browser cache beforehand meant the malicious file was already present locally when the command ran, helping it slip past detection methods that focus on downloads and also getting around length limits in the Run dialog.

What to Watch For

  • A CAPTCHA or verification prompt that asks you to open Windows Run or a terminal
  • Instructions to paste clipboard contents and press Enter to "verify" you are human
  • Any step that pushes you from a web page into an operating system action rather than a normal browser interaction

As Microsoft noted, a CAPTCHA should not ask users to run code. That single red flag is often enough to stop the chain before it starts.

Building Resistance

Organizations should train all employees, not just IT staff, to recognize ClickFix-style pretexts as a known malware delivery method. Because this technique relies on a single user action rather than a complex exploit, awareness at the point of the fake prompt is a critical control.

For security operations and endpoint administrators, detection should not rely solely on download alerts. Monitoring browser activity alongside unusual WScript, PowerShell, and scheduled-task activity, as well as reviewing the RunMRU registry key, can help catch this technique even when the payload itself avoids traditional download-based detection.

Key findings

  • Compromised websites led visitors to a ClickFix-style fake verification step (fake CAPTCHA).
  • Victims were instructed to open Windows Run and execute a command pasted from the clipboard.
  • The VBScript payload was pre-fetched into the browser cache and disguised as an image so it was already on disk when executed.
  • The command searched cached files (names starting with "f_") and matched the payload by file size, then copied it as a .vbs file and executed it with wscript.exe.
  • The VBScript collected host details via WMI, fetched and ran a PowerShell script with execution policy bypassed, and later injected code into timeout.exe.
  • Persistence was established using a scheduled task that ran a Python payload via pythonw.exe after unpacking Python with tar.exe.
  • Microsoft Defender detects this behavior as Trojan:Win32/ClickFix and Trojan:Win32/TermFix.
  • Microsoft advised hunters to look beyond downloads to browser activity, WScript/PowerShell/scheduled task events, and the RunMRU registry key.

Who’s being targeted

  • Commonly targeted roles: All Employees, IT Helpdesk, Security Operations (SOC), Endpoint/IT Administrators.
  • Affected industries: General / cross-industry (any web-browsing Windows users).
  • Attack channels: website.
  • Impersonated: CAPTCHA / website verification prompt.

Red flags to watch for

  • A CAPTCHA should not ask you to run commands on your computer
  • Instructions to use Windows Run and execute clipboard contents is highly unusual
  • The step bypasses normal web verification flows and pushes OS-level actions
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is a ClickFix attack?

ClickFix is a social engineering technique that gets victims to run attacker-supplied commands under the guise of a verification step, such as a fake CAPTCHA.

How does the fake CAPTCHA infect a computer?

The fake CAPTCHA pop-up tells users to open Windows Run, paste clipboard contents, and press Enter, which executes a command that locates a VBScript payload already cached in the browser disguised as an image.

Why is hiding the payload in browser cache significant?

Because the file is already on disk before the victim runs the command, the attack can evade simple download-based detection and bypass character limits in the Run dialog.

What should defenders monitor for this kind of attack?

Microsoft advised looking beyond download events to browser activity, unusual WScript, PowerShell, and scheduled-task activity, as well as the RunMRU registry key.

Read the video transcript

You solve a CAPTCHA, and then it says: "Open Windows Run, paste from your clipboard, press Enter." That is ClickFix. Behind that fake CAPTCHA, the site already stashed a VBScript in your browser cache, disguised as an image. The Run command just hunts for that hidden file and launches it with wscript.exe. Once it runs, it pulls PowerShell with execution policy bypassed, injects into timeout.exe, and drops a scheduled task that later runs a Python payload in the background. Microsoft flags this as Trojan:Win32/ClickFix and TermFix. A CAPTCHA should never tell you to open Run or paste commands. If any site does that, stop immediately and report it to Security, do not press Enter.

Similar attacks

Law Firm Hit by Phish Using Fake Python Runtime

Law Firm Hit by Phish Using Fake Python Runtime

Researchers say a law firm was targeted with a spear‑phishing email that led staff to download an encrypted archive containing a Windows shortcut labeled like legal case files. After the user ran it and approved admin rights, the malware told Microsoft Defender to ignore a folder and a fake…

August 3, 2026
ClickFix Lures Spread ChainScript RAT

ClickFix Lures Spread ChainScript RAT

Researchers describe real-world “ClickFix” social-engineering lures that trick people into installing malware by downloading fake apps (like Spotify/Zoom/Teams) or copying commands into Terminal. One campaign abused a compromised, verified HBO Max Reddit account to run malicious ads, while another…

September 21, 2026
“TTF Trap” Uses Fake Font Files to Drop Malware

“TTF Trap” Uses Fake Font Files to Drop Malware

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by…

July 17, 2026
Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Fake Zoom/Webex Installers Drop Starland RAT

Fake Zoom/Webex Installers Drop Starland RAT

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools like Zoom, Webex, and MobaXterm. Victims are socially engineered via a “ClickFix” style trick into running a command that silently…

July 17, 2026
Star Blizzard’s RedFlick Phish Uses VHDX Trap

Star Blizzard’s RedFlick Phish Uses VHDX Trap

Microsoft reports real-world Star Blizzard phishing campaigns where victims who engage with an initial email receive a follow-up message containing a password-protected ZIP/RAR attachment. The attachment chain hides a malicious shortcut disguised as a PDF, opening a decoy file while quietly…

September 30, 2026