ClickFix Scams: How to Spot Fake CAPTCHA Attacks

Share this post on social...

ClickFix scams are a form of social engineering that trick people into performing actions that can expose their computers to malware. Instead of simply asking victims to download a suspicious file, scammers may use fake CAPTCHA tests, browser errors, security alerts, or software-update messages to persuade users to copy and run commands.

The technique has become a significant cybersecurity concern. Microsoft has reported ClickFix campaigns targeting Windows and macOS devices, while Switzerland’s National Cyber Security Centre reported in August 2026 that more than 100,000 websites worldwide had been affected by compromised websites using fake CAPTCHA-style attacks.

What Is a ClickFix Scam?

ClickFix is a social-engineering technique designed to make a malicious action appear like a legitimate troubleshooting or verification step.

For example, you might visit a website and see a message claiming:

  • “Verify that you are human.”
  • “Your browser needs to be updated.”
  • “An error occurred while loading this page.”
  • “Follow these steps to continue.”
  • “Copy and paste the verification command.”

The page may then instruct you to use keyboard shortcuts, open Windows Run, PowerShell, Command Prompt, or Terminal, and paste something into the window.

This is where the danger begins.

Microsoft explains that ClickFix attacks commonly rely on victims copying, pasting, and executing malicious commands themselves. These campaigns can ultimately lead to information theft and malware infections.

Important: A legitimate CAPTCHA should not require you to execute an unknown command on your computer.

How ClickFix Attacks Work

A ClickFix scam commonly follows a sequence like this:

  1. You visit a malicious, compromised, or deceptive website.
  2. A fake CAPTCHA, browser error, or security message appears.
  3. The page tells you that an additional verification or repair step is necessary.
  4. You are instructed to copy something or use a keyboard shortcut.
  5. You are encouraged to paste the content into a system utility.
  6. The command may download or launch unwanted software.
  7. The malware may attempt to steal information or compromise the device.

Microsoft has documented ClickFix campaigns delivered through phishing, malicious advertising, and compromised websites.

Why Are ClickFix Scams Dangerous?

ClickFix attacks take advantage of something that makes traditional cybersecurity defenses more difficult: the victim is persuaded to participate in the attack.

Rather than automatically exploiting a vulnerability, the scam attempts to convince the user that they are fixing a technical problem.

The Center for Internet Security describes ClickFix as a social-engineering technique that can be used to distribute malware and facilitate data or financial theft.

This is why cybersecurity awareness is particularly important.

Common Signs of a ClickFix Scam

1. A CAPTCHA Tells You to Open Windows Run

Be suspicious if a CAPTCHA or verification page instructs you to press Windows + R.

Windows Run is a legitimate operating-system feature, but a random website should not be asking you to use it to complete a CAPTCHA.

2. You Are Asked to Paste a Command

One of the strongest warning signs is being told to copy and paste text into:

  • Windows Run
  • PowerShell
  • Command Prompt
  • Windows Terminal
  • macOS Terminal

If you don’t understand what the command does, don’t run it.

The University of Oregon specifically warns users to stop if a CAPTCHA or pop-up asks them to use keyboard commands, copy and paste text, or open Terminal or Windows Run.

3. A Fake Browser Error Appears

Some ClickFix campaigns imitate browser crashes or technical errors.

Others may make a page look like a legitimate service is experiencing a temporary problem.

The goal is to make the visitor believe that following the displayed instructions is necessary to continue.

4. The Page Looks Like a Familiar Security Service

ClickFix campaigns have been observed impersonating familiar services and verification systems.

Microsoft has documented examples involving fake reCAPTCHA and Cloudflare Turnstile-style pages, as well as pages impersonating other legitimate services.

A familiar-looking logo does not prove that the page is genuine.

5. The Page Creates a Sense of Urgency

Be cautious when a website tells you:

  • “Act now.”
  • “Verification required.”
  • “Your browser is outdated.”
  • “Fix the problem immediately.”
  • “Complete this step to continue.”

Scammers often use urgency to discourage users from investigating.

Where Can ClickFix Scams Appear?

ClickFix attacks can be delivered through several channels, including:

Compromised Websites

A legitimate website may be compromised and modified so that visitors are redirected to a malicious verification page.

Malicious Advertisements

Some users may encounter ClickFix pages after interacting with deceptive advertisements or redirects.

Phishing Emails

Attackers can send emails containing links that lead to fake verification pages.

Search Results

Malicious or compromised websites can sometimes appear through search-related traffic, making it important to verify websites before following unusual instructions.

Fake Software Updates

A page may claim that your browser, media player, or another application needs an immediate update.

Instead of clicking the suspicious prompt, open the software’s official website or built-in update feature.

Are ClickFix Scams Only a Windows Problem?

No.

ClickFix has also been used against macOS users.

Microsoft has documented campaigns that attempted to trick Mac users into executing commands associated with malware such as Atomic macOS Stealer.

Therefore, both Windows and Mac users should be cautious when a website asks them to execute unfamiliar commands.

How to Protect Yourself From ClickFix Scams

Never Execute Unknown Commands

This is the most important precaution.

If an unfamiliar website tells you to copy and paste a command into your computer, stop and verify the instructions before doing anything.

Don’t Trust a CAPTCHA That Requires Command-Line Instructions

A normal CAPTCHA is designed to distinguish humans from automated systems.

It should not require you to execute a command in Windows Run, PowerShell, Command Prompt, or Terminal.

Close Suspicious Pages

If a webpage suddenly displays a strange security warning or fake verification process, close the browser tab.

You do not need to follow the instructions simply because the page claims that you must.

Keep Your Browser and Operating System Updated

Install updates through your device’s normal update mechanism or the software developer’s official website.

Avoid downloading updates from unexpected pop-ups.

Use Reputable Security Software

Keep your device’s built-in security protections enabled and ensure your security software is up to date.

For Windows users, you can learn more about Microsoft’s security protection through the official Microsoft Security website.

Be Careful With Online Advertisements

Avoid clicking suspicious advertisements, particularly when they redirect you through several unexpected pages.

If an advertisement suddenly claims your device has a serious problem, close the page rather than calling a number or installing software from the pop-up.

What Should You Do If You Already Followed a ClickFix Scam?

If you already copied and executed a command from a suspicious website, don’t panic, but take the situation seriously.

1. Stop Using the Suspicious Website

Close the browser tab and avoid interacting with the page again.

2. Disconnect the Device if You Suspect Malware

If you believe malicious software may have been installed, disconnecting the device from the internet can help limit unwanted communication while you investigate.

3. Run a Security Scan

Use your trusted security software to perform a thorough scan.

Windows users can consult the official Microsoft Defender information page for guidance on Windows security features.

4. Change Important Passwords

If you suspect that credentials may have been exposed, change important passwords from a trusted device.

Prioritize your email, financial, shopping, social-media, and other important accounts.

5. Enable Multi-Factor Authentication

Where available, turn on multi-factor authentication for important accounts.

This provides an additional security layer even if a password is compromised.

6. Monitor Your Accounts

Watch for unfamiliar login notifications, password-reset messages, purchases, or other unusual activity.

If you notice suspicious financial transactions, contact your bank or financial institution through its official contact channels.

7. Get Professional Help if Necessary

If malware is detected or your device continues behaving unusually, consider contacting a qualified computer-security professional.

ClickFix Scams vs. Traditional Phishing

FeatureTraditional PhishingClickFix
Main tacticDeceptive message or websiteSocial engineering
Common lureFake login, attachment, or linkFake CAPTCHA, error, or update
Victim actionClick, download, or enter informationCopy, paste, and execute
Potential riskCredential theft or malwareMalware, information theft, or unauthorized access
Human interactionImportantCentral to the attack

ClickFix can also be combined with phishing, malicious advertising, and compromised websites.

How to Tell a Real CAPTCHA From a ClickFix Scam

A legitimate CAPTCHA normally asks you to complete a verification challenge within the webpage.

A suspicious ClickFix-style CAPTCHA may instead ask you to:

  • Press Windows + R.
  • Open PowerShell.
  • Open Command Prompt.
  • Open Terminal.
  • Copy and paste text.
  • Run a command.
  • Download an unfamiliar program.
  • Disable security software.

If the “CAPTCHA” requires any of these actions, leave the page.

Frequently Asked Questions

Is ClickFix a virus?

No. ClickFix is a social-engineering technique rather than a specific virus. Attackers use it to persuade people to execute commands that may download or launch malware.

Can a fake CAPTCHA infect my computer?

A fake CAPTCHA itself may simply be a webpage, but following its instructions can result in malicious commands being executed and malware being downloaded.

Does pressing Windows + R automatically infect my computer?

No. Simply opening Windows Run does not automatically mean that your computer has been infected. The major risk comes from following the scam’s instructions and executing an unknown command.

Can ClickFix affect Mac computers?

Yes. Security researchers have documented ClickFix campaigns targeting macOS as well as Windows.

Can ClickFix steal passwords?

Depending on the malware delivered, attackers may attempt to steal browser credentials, cookies, financial information, cryptocurrency-wallet information, or other sensitive data.

What should I do if a CAPTCHA tells me to copy and paste a command?

Do not do it. Close the page and access the website or service through its official website or application.

Final Thoughts

ClickFix scams show how cybercriminals increasingly rely on social engineering rather than simply exploiting technical vulnerabilities.

The safest approach is to slow down whenever a website suddenly asks you to perform an unusual action.

A CAPTCHA should not require you to open PowerShell, Windows Run, Command Prompt, or Terminal and execute an unknown command.

If a webpage tells you to copy, paste, run, or execute something to “fix” a problem, stop and verify it first.

Useful Cybersecurity Resources

For additional information and security guidance, readers can consult:

Related Security Guides

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *