ScamsTech supportThe fake CAPTCHA ("ClickFix") scam: when "prove you're human" really means "run our malware"
High

The fake CAPTCHA ("ClickFix") scam: when "prove you're human" really means "run our malware"

A page asks you to verify you are human by pressing a few keys — Windows + R, then Ctrl + V, then Enter. Those keystrokes do not prove anything. They paste and run malware you cannot see. Here is how to recognize it.

Sources checked:FTCCISA

We have all been trained to breeze through “prove you’re human” checks — tick a box, pick the buses, move on. A scam called ClickFix weaponizes exactly that reflex. Instead of an image puzzle, the fake CAPTCHA hands you a short set of keystrokes to “verify” or “fix” something. Follow them and you are not proving anything — you are running malware on your own device.

How the trick works

The FTC lays it out: you get an unexpected CAPTCHA-style prompt, and “the message says to type a series of commands — something like ‘Windows + R,’ then ‘Ctrl + V,’ and then ‘Enter.’” The screen “might say security verification”, but those steps actually “paste and run hidden malware on your device.”

Security agencies track this under the name ClickFix. CISA describes it as “a social engineering technique where unsuspecting users are prompted to execute a malicious payload by clicking a fake CAPTCHA.” The mechanics: you are told to “open the Windows Run window, paste the clipboard contents, and then execute a malicious Base64-encoded PowerShell process.” The crucial part is invisible — the page has already copied a hidden command into your clipboard, so when you paste and hit Enter, you launch it yourself. The technique has been used to deliver ransomware (CISA documents it in Interlock activity) and information-stealing malware such as Lumma Stealer.

Why it slips past people

This scam borrows the trust of two familiar things at once: the CAPTCHA you have clicked a thousand times, and the idea that “following the on-screen steps” is how you fix a glitch. There is no phone number to call and no obvious villain — just a routine-looking checkbox and some instructions. That ordinariness is the disguise.

The one rule that stops it

Here is the line to remember: a real human-verification never asks you to run commands. As the FTC puts it, “real CAPTCHAs won’t ask you to run commands on your device” — they ask you to match images or type characters you see. So the instant a “verification” or “error fix” tells you to press Windows + R, open a Terminal, or paste something, treat it as an attack and close the page.

This is a newer cousin of the tech-support pop-up scam: both fake an urgent computer problem, but instead of telling you to call a number, ClickFix gets you to run the malware yourself. The defense is the same instinct — Go Direct: never act on the page that raised the alarm; if you think something is genuinely wrong, open your real antivirus app or the official site yourself.

If you already followed the steps, disconnect from the internet, run a security scan, update your software, and change your passwords with two-factor authentication turned on. For more, see the defense library or test your eye on the 60-second quiz.

Warning signs
  • A "CAPTCHA" or "verification" step asks you to press keys like Windows + R, then Ctrl + V, then Enter — instead of the usual image or text puzzle.
  • The page says it is a "security verification", "human check", or a fix for an error you did not have a moment ago.
  • You are told to open a Run box, the Terminal, or to paste something you did not knowingly copy.
  • It appears after clicking a link, an ad, or a "watch the video / download the file" prompt.
  • Something starts downloading or your device behaves oddly right after you follow the steps.
Defense move — Go Direct
  • No real CAPTCHA, website, or error message ever asks you to open a command box or run keyboard commands. If a page gives you steps like "Windows + R, Ctrl + V, Enter", it is an attack — close the tab.
  • Real human-verification asks you to match images or type characters you see. As the FTC notes, "real CAPTCHAs won't ask you to run commands on your device."
  • Never paste and run something you did not knowingly copy. The malware is hidden in your clipboard, so the paste is the payload.
  • If you think your device or an account has a real problem, go to the official app or site yourself — do not follow instructions handed to you by the page that raised the alarm.
  • If you already ran the steps, disconnect from the internet, run a security scan, update your software, and change your passwords with two-factor authentication on.
Editor's note

What makes this one nasty is that it turns a habit we have been trained into — clicking through CAPTCHAs without thinking — into the attack itself. The defense is a single, memorable line: a real human-check never asks you to run anything. The moment a 'verification' hands you keyboard commands, you are not proving you are human; you are being asked to infect your own machine. Close the tab.

Frequently asked

It looked like a normal "I'm not a robot" check. How is that dangerous?

Because the check is fake. A real CAPTCHA gives you an image or text puzzle; this one gives you keyboard commands to run. The FTC describes the trick: a message says to type "Windows + R", then "Ctrl + V", then "Enter", and while "the screen might say security verification", you are actually following "the steps to paste and run hidden malware on your device."

What does pressing those keys actually do?

Security agencies call this technique "ClickFix". CISA describes it as instructing you to open the Windows Run box, paste the clipboard contents, and execute a hidden command — in their words, "a malicious Base64-encoded PowerShell process." The malicious command was secretly copied to your clipboard by the page, so pasting and pressing Enter runs it.

I pressed the keys before I realized. What should I do now?

Act quickly. Disconnect the device from the internet to cut off the attacker, run a security scan to find and remove malware, update your software, and then change your important passwords — ideally from a different, clean device — and turn on two-factor authentication. The malware often aims to steal passwords and account access.

How do I avoid this in the first place?

Treat any verification or error that asks you to run commands, open the Run box or Terminal, or paste something as a scam, and close the page. Keep your browser and operating system updated, and be wary of "watch / download" prompts on unfamiliar sites, which are common entry points.

RY
Ryon — Founder & Editor
Consumer-safety advocate · Scamblare

Scamblare researches scams every day so you don't have to. Every article is checked, claim by claim, against primary sources like the FTC and FBI IC3 under our published editorial standard. How we fact-check ›