← All articles

"Confirm you're not a robot": the fake CAPTCHA trap

A checkbox, a familiar logo, a security check. Then the site asks you to open a window on your computer and paste some text. That is the moment to stop: the fake CAPTCHA is trying to get you to launch the attack yourself.

"Confirm you're not a robot": the fake CAPTCHA trap

An assistant is looking for a spec sheet to finish a quote. She finds the right site — a supplier she knows. Before the document, a check appears: "Confirm you're not a robot."

The logo is familiar. The layout is clean. She ticks the box.

A second step appears. To complete the verification, she needs to press three keys — Windows, R, then Ctrl-V — and Enter. The site presents it as a formality. She wants her document. She does it.

A small black window opens and closes. Nothing else happens. The PDF appears. She finishes her quote and moves on to the next file.

Three weeks later, someone signs in to the payroll portal with her credentials. Then to her bank, with the password saved in her browser. Then to Microsoft 365 — without even needing her authentication code, because her browser session had been copied too.

Her computer never slowed down. No warning appeared. The antivirus said nothing.

She did nothing stupid. She did exactly what a credible page asked her to do, on a normal working day, to get a document she needed.

The one rule to remember

A web page, an email or a Teams conversation asks you to open a window on your computer and paste something into it? Stop. Nobody legitimate asks for that.

Not Google, not Cloudflare, not Microsoft, not your IT department. No real security check takes you out of your browser to run a command.

You do not need to understand what the command does. You do not need to judge whether it looks harmless. The mere fact that you are being asked to do this is enough to close the page and message IT support.

What is actually happening, in thirty seconds

When you tick the box, the page quietly slips some text into your clipboard — where things you copy go. You do not see it.

Then it tells you to open the Run window, PowerShell or Terminal, and paste. What you paste is not a verification code. It is a complete instruction that your computer executes the moment you press Enter.

And because you pressed Enter, nothing fires. No download warning, no "this file may be dangerous" prompt, no first-stage antivirus alert. The system assumes you know what you are doing.

Specialists call this ClickFix. It is not a virus: it is a way of getting you to launch the virus yourself.

It doesn't always look like a CAPTCHA anymore

The checkbox was the first form. In 2026 the same trap shows up in several ways, and some are far more convincing.

On a site you know. Australia's cyber security centre documented attacks in May that used the websites of real businesses — compromised without their knowledge — to slip the fake check into a perfectly normal visit. The address in the bar is correct. The site is the right one. Only the verification is fake.

In a Teams conversation. Since spring, attackers have been contacting employees directly in Microsoft Teams, from outside the organization, posing as the help desk. They describe a problem on your machine and walk you through it: open PowerShell, paste this, press Enter. In the cases studied, the conversation led to permanent access to the computer in under five minutes. Remember this: your real IT department will never contact you from an account outside the company.

In an AI tool installation guide. You want to try an AI assistant a colleague mentioned. You search for how to install it. The first result — an ad — gives you a command to paste into Terminal or PowerShell. The command installs something else. This variant is growing fast because it targets people who genuinely want to install something.

In a browser that seems to crash. A page deliberately freezes or crashes your browser, then offers to "fix" the problem by running a command. The problem was the trap.

On Macs too. Campaigns targeting macOS ask you to open Terminal instead of PowerShell, and distribute information stealers built for Mac. Apple responded in the spring by adding a protection that analyzes commands pasted into Terminal and warns the user. Attackers worked around it within weeks by moving the manoeuvre to a different application. The lesson applies to every device: technical protection helps, but your reflex decides.

In every one of these cases the rule does not change: you are being asked to leave your browser or your conversation to run something. That is the signal.

Why your protections saw nothing

It is fair to ask what antivirus and web filtering are for if a trap like this gets through.

First, there is often nothing to download. The command you paste fetches the rest itself once it runs. No suspicious file lands in your downloads folder.

Second, the trapped pages know how to hide. Microsoft documented a campaign in August whose pages first checked whether the visitor looked like a real human on a real computer — and showed the trap only to them. When an automated security tool looked at the page, it was clean. When you looked at it, it was not.

Finally, the software that gets installed is built to be quiet. The most widespread information stealer in these campaigns deletes its own file after launching and runs only in memory. Your computer keeps working normally — because the program has no interest in being noticed.

What it takes: the passwords saved in your browser, your open sessions, access to any digital wallets you have, and information about your system. The open sessions are the most serious: they sometimes let the attacker sign in to your accounts without a password and without your authentication code, simply by reusing your already-validated session.

You saw the page but ran nothing

Close it. Message IT support with the site address and exactly what you did: ticked a box, entered a password, downloaded something, or nothing at all.

Do not paste your clipboard contents anywhere "to see what it is." Pasting into a Word document or a notepad is harmless; pasting into a command window is not, and the difference is not always obvious under pressure.

Seeing the page does not mean you are infected. But the details you provide let IT pick the right checks.

You pasted the command and pressed Enter

Report it now. Not tomorrow, not after finishing the file you are on. Reacting within minutes completely changes what IT can still do.

  1. Stop using the machine and contact support from another device — your phone, a colleague — using the usual contact details.
  2. Disconnect it from the network: cable and Wi-Fi. Or ask IT to isolate it immediately.
  3. Do not restart, do not clean anything, do not clear the history. What remains on the machine helps explain what happened.
  4. Note the time, the page or conversation, and what you did. If an email or message led to the page, keep it without reopening the link.
  5. Do not change your passwords from that machine. The information stealer may still be watching. IT will tell you which device to use.

Not sure whether you pressed Enter? Report that uncertainty as-is. Do not try to reproduce the steps to check.

And one thing the IT department needs to hear clearly: the person who reports a mistake within five minutes has probably saved the company from an incident. They do not deserve a sigh. They deserve a thank you.

For the owner forwarding this article

Five lines, no more.

  • Forward this to the whole team, not just the "at-risk people." The assistant in the story was looking for a spec sheet. Everyone looks for documents.
  • Ask your IT to restrict Teams conversations from outside the organization to an approved list of partners. It is a setting, not a project, and it closes the door on the most effective variant.
  • Make sure endpoint monitoring is in place and that someone — in-house or at your provider — can isolate a machine quickly. Without that, the employee who reports properly gets nothing for it.
  • Check that web and email filtering is on, knowing it will not catch everything. Training is not a supplement; it is the first line.
  • Give your employees explicit permission to stop, even when the document is urgent and the client is waiting. It is the only protection that works in every case described here.

In closing

The assistant in our story wanted to finish her quote. That is a perfectly reasonable goal, and the trap counts on it: it places itself between you and what you are trying to do, then offers a shortcut.

The shortcut looks like a formality. Three keys, Enter, and the document appears.

What you need to know is that at that precise moment, stopping is the right move — even if it delays the file by ten minutes. Those ten minutes cost far less than what follows if you keep going.

A verification asks you to paste something on your computer? Stop. Message support. And if you already did it, message anyway — right now.

An IT project or a question?

MMO Techno can support you with fake CAPTCHA awareness, verifying your endpoint protections, and preparing the reporting and response reflexes.

Talk to an MMO Techno expert .

An IT project or a question?

Talk to an MMO Techno expert. We'll give you a clear, fast answer.

Contact us