A genuine CAPTCHA stays inside the webpage; a fake one may pressure you to open system tools, paste commands or download a supposed fix.
A familiar design can hide an unsafe instruction
Attackers imitate CAPTCHA and browser-verification screens because people recognise them and want to continue. The visual design is not proof that Cloudflare, Google or another provider created the prompt.
The clearest distinction
A normal verification challenge asks you to click, select images or complete an interaction inside the browser. It should not tell you to open Windows Run, Terminal or PowerShell, paste clipboard content, disable security software or install an update from an unfamiliar address.
Interaction remains in the page and does not require commands or system settings.
Moves you into an operating-system tool or asks you to run concealed content.
If the prompt appears after a delay
Do not assume the earlier page was safe. Some campaigns delay or condition the malicious stage. Close the tab, preserve the URL as text for defenders and check the destination through a restricted scanner.
If you followed the steps
Disconnect from sensitive services, contact security support, and explain exactly which steps were completed. Change exposed passwords from a known-clean device. Do not rerun the instructions to demonstrate what happened.
Reference: Microsoft Security Intelligence on FakeCaptcha.