Security guides

Fake CAPTCHA Malware: Warning Signs and Response

Learn how fake CAPTCHA pages deliver malware and how to distinguish a normal web challenge from dangerous command instructions.

A genuine CAPTCHA stays inside the webpage; a fake one may pressure you to open system tools, paste commands or download a supposed fix.

A familiar design can hide an unsafe instruction

Attackers imitate CAPTCHA and browser-verification screens because people recognise them and want to continue. The visual design is not proof that Cloudflare, Google or another provider created the prompt.

The clearest distinction

A normal verification challenge asks you to click, select images or complete an interaction inside the browser. It should not tell you to open Windows Run, Terminal or PowerShell, paste clipboard content, disable security software or install an update from an unfamiliar address.

Normal browser challenge

Interaction remains in the page and does not require commands or system settings.

Dangerous imitation

Moves you into an operating-system tool or asks you to run concealed content.

If the prompt appears after a delay

Do not assume the earlier page was safe. Some campaigns delay or condition the malicious stage. Close the tab, preserve the URL as text for defenders and check the destination through a restricted scanner.

If you followed the steps

Disconnect from sensitive services, contact security support, and explain exactly which steps were completed. Change exposed passwords from a known-clean device. Do not rerun the instructions to demonstrate what happened.

Reference: Microsoft Security Intelligence on FakeCaptcha.

Continue learning

Explore the detection catalogue.

Browse detectionsCheck a link