Schneier iconSchneierSep 16, 2026 ~7 min source read

Fake CAPTCHA Scams: Attackers Turn a Familiar Security Check into a Delivery Mechanism

A recent wave of scams uses fake CAPTCHA prompts to trick visitors into downloading and executing malicious code. The technique cloaks malware delivery in a routine verification flow and has appeared in multiple variants, including chains that fingerprint devices and serve targeted payloads.

Share this story

Send the public story page.

Useful takeaways from this story.

Attackers inject fake CAPTCHA prompts that instruct users to download or run commands — legitimate CAPTCHAs never require running software or pasting terminal commands.

Campaigns use device and network fingerprinting to serve different payloads to residential or mobile IPs, while showing clean pages to scanners and datacenter IPs.

Observed variants include delivery of credential- and crypto-stealing malware via chains using WebDAV, Cloudflare Workers, blockchain-hosted instructions, and vulnerable drivers to disable endpoint protection.

# What happened

Security researchers and commentators have documented a renewed wave of "fake CAPTCHA" scams. These attacks present visitors with what looks like a normal human-verification prompt but then instruct the user to download and run software or paste a command into a system dialog. The action the page asks for is the attack itself.

# How the scam works

Attackers compromise legitimate websites or inject malicious code into pages. The injected script displays a CAPTCHA-style UI and tells the user to perform steps such as pressing Windows+R and pasting a supplied command. The command downloads and executes a small script or DLL (examples in commentary include use of curl to fetch a.sct script and regsvr32 to register it).

# Variants and capabilities observed

  • Targeted payloads: Reported campaigns deliver credential-stealers and crypto stealers. One chain reported in September ties together fake Google CAPTCHA prompts, WebDAV-hosted DLL execution, Cloudflare Workers, and BNB Smart Chain instructions to deploy the Amatera information stealer.
  • Evasion techniques: TDS fingerprinting selectively serves payloads. Some operators use blockchain-hosted instructions and cloud-worker edge infrastructure to hide command-and-control details.
  • Endpoint compromise: At least one named campaign (ClearFake) includes a crypto stealer that uses a vulnerable driver to disable EDR products, increasing persistence and impact.

# Why this works

People are accustomed to CAPTCHAs as a routine verification step. Attack pages exploit that familiarity by presenting the malicious action as a legitimate step in completing the CAPTCHA. The TDS filtering means innocent reporters and security tools may not see the malicious behavior, which helps the operation remain active longer.

# Concrete user guidance

  • Close the page immediately if a CAPTCHA asks you to download software, open a terminal, or run a system command. A genuine CAPTCHA will never require those steps.
  • Never paste commands you don't understand into a Run box or terminal. Treat copied commands as code with the same risk as running downloaded executables.
  • Check links in messages and use bookmarks for important sites instead of following unsolicited links.

# What organizations should do

  • Monitor for unauthorized script injections and remote-hosted resources (WebDAV, third-party workers) on web properties.
  • Look for evidence of TDS-style fingerprinting that selectively serves different content based on IP or user agent.
  • Use robust content-security policies and integrity checks on web assets to detect and block tampered resources.
  • Educate users with a clear rule: CAPTCHAs never ask you to run commands or install software.

# Notable public reports and incidents

  • Media reporting linked the technique to thousands of compromised sites. One summary reported more than 5,400 legitimate sites serving fake CAPTCHA scams.
  • Investigations tied click-to-run command flows to larger operations delivering credential- and crypto-stealing malware, and to high-profile incidents such as a ClickFix variant implicated in a ransomware event affecting Berlin authorities.

More context around this story.

Why That Scam Link Looked Harmless When You Checked It
Geekmamas iconGeekmamasSep 11, 2026

Why That Scam Link Looked Harmless When You Checked It

Phishing scams often use cloaking to display fake login pages only to targeted devices, typically smartphones. When reported, these pages may show as harmless or blank on other devices. Users should avoid opening suspicious links and report them instead, focusing on message content for signs of fraud. The post Why That

Misc
Blogspot iconBlogspotSep 10, 2026

Misc

Misc Miscellaneous category. No Placement. A lot a great resin crafts. <img border="0" data-original-height="961" data-ori...

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app