Scam Defence

Fake CAPTCHA Scams: Never Paste a “Verification” Command

Some fake CAPTCHA pages tell visitors to paste a command that installs malware. Learn the warning signs and the safe response.

Muhammad Azhar August 14, 2026 Reviewed August 21, 2026 3 min read

A legitimate CAPTCHA may ask you to select images, tick a box or complete a browser challenge. It does not need you to open PowerShell, Terminal or the Windows Run dialog and paste a command. That instruction is the scam.

Why the trick works

The page copies a hidden command to the clipboard, then presents keyboard steps as “verification.” Pasting and running it gives the command the user's own permission, allowing malware or an infostealer to download.

Stop at these instructions

  • Press Windows+R, Win+X or open Terminal.
  • Paste from the clipboard without showing the command.
  • Disable security software to finish verification.
  • Install a browser update from an unfamiliar page.

If you already ran the command

Disconnect the device from the network, contact workplace IT if applicable and use a clean device to protect email and financial accounts. End active sessions, not only passwords, because infostealers target browser cookies. Preserve the URL and command for incident response.

Closing the page before executing anything is enough. A website can verify browser behavior inside the page; it should never ask for operating-system commands as proof that you are human.

Why antivirus may not stop the first step

The user is executing the command through a trusted operating-system tool, so the initial action may resemble legitimate administration. Later downloads may be detected, but prevention is stronger: browsers do not need shell access to confirm a human visitor.

For workplace teams

Block known campaign domains, restrict script interpreters where operationally possible and teach staff one memorable rule: a CAPTCHA stays inside the webpage. Preserve the copied command for analysis rather than running it in a test production device.

Understand the clipboard trick

The page may silently place a command on the clipboard and then tell the visitor to press a keyboard sequence. The command can download a second program, steal browser data or establish persistence. The visible “verification code” may not match what is actually pasted.

Containment after execution

Disconnect the affected device, note the time and exact page, and contact a qualified responder. From another trusted device, protect email, password-manager and financial accounts, revoke sessions and review security alerts. Simply deleting browser history does not undo a command that ran through the operating system.

Organizations can reduce exposure with application control, restricted scripting, browser protections and training that uses one clear rule: a website never needs a person to paste an operating-system command to prove they are human.

A CAPTCHA never needs an operating-system command

ClickFix pages imitate a browser verification step, then instruct the visitor to open a Run dialog, terminal or PowerShell window and paste text. The clipboard may contain a longer command than the page displays. Running it can download malware, steal browser sessions or create persistence under the user's own account.

Stop as soon as a website asks for keyboard shortcuts outside the browser. Closing the tab is safe. Do not paste the command into a chat or public scanner because it may contain a unique identifier or active download address. Security teams should capture it through an isolated analysis process.

Respond as if credentials may be exposed

If the command ran, disconnect the device from the network and record the page, time and visible instructions. Use another trusted device to secure email, password-manager and financial accounts, revoke active sessions and contact the organization responsible for the computer. A quick antivirus scan is useful evidence but is not proof that the device is clean.

For prevention, restrict unnecessary script interpreters, use application control and teach one memorable rule: browser verification happens in the browser. It never requires a person to execute a system command.

Sources and further reading