You open a page you've visited a dozen times. Before it loads, a familiar box appears: the Cloudflare "Verify you are human" check, or Google's "I'm not a robot" tickbox. You click it. Instead of letting you through, it shows three short steps: press the Windows key and R, press Ctrl+V, press Enter. It even calls it a "verification code."
That box isn't Cloudflare or Google. It's a scam, and the "code" it asked you to paste is a command that downloads malware onto your machine. You didn't open an attachment or install anything. You ran it yourself, because the page asked nicely and looked exactly like something you've clicked a thousand times before.
This guide covers what these fake checks look like, why they work on careful people, why they're still one of the biggest headaches for businesses in 2026, and what to do if you've already pasted the command.
The disguises: fake Cloudflare, reCAPTCHA and other checks#
Fake CAPTCHAs borrow the look of things we've all been trained to click through without thinking. The most common costumes:
| Disguise | What you see | What it asks you to do |
|---|---|---|
| Fake Cloudflare check | The "Verify you are human" / "Checking your browser" box in Cloudflare's style, sometimes with a fake Ray ID | Press Win+R, paste, Enter |
| Fake Google reCAPTCHA | The "I'm not a robot" tickbox, then a "verification steps" pop-up | Paste a "verification code" into the Run box |
| Fake hCaptcha / Turnstile | Any of the other human-check widgets you see on login and signup pages | Same steps, different logo |
| Fake browser error | "This page can't be displayed correctly" or "Fix the font error" | Open PowerShell or Terminal and paste a "fix" |
| Fake update screen | A full-screen Windows Update, Chrome update or macOS update page | Press Win+X then I (opens Terminal as admin) and paste |
| Fake file share | "Open this shared document" with a file path to copy | Paste the "path" into the File Explorer address bar |
| Fake AI install guide | A tidy "how to install" page for an AI tool, sometimes hosted on a real AI platform's sharing feature | Paste an install command into Terminal |
| Fake Mac check | A Cloudflare-style check that detects you're on a Mac | Open Terminal (Cmd+Space, type Terminal) and paste |
The look changes constantly; the ask never does. Every version ends with you pasting something into a box that runs commands: the Run box (Win+R), PowerShell, Windows Terminal, the File Explorer address bar, or the Mac Terminal.
Here's the rule that beats every variant: a real CAPTCHA asks you to click, tick or pick pictures. It never asks you to press keys on your keyboard, open a program, or paste anything. Cloudflare's real check either passes you silently or shows a single tickbox. Google's reCAPTCHA asks you to tick a box or click on traffic lights. Neither has a step 2.
How the attack works, step by step#
1) You land on a page that's been tampered with#
Most victims don't arrive through a dodgy email. They come from a search result, a sponsored ad, or a perfectly normal website that's been hacked. In its September 2026 analysis, Push Security found that four in five of these payloads it intercepted arrived via search engines - SEO poisoning, malicious ads and compromised sites - not email. The same report counted more than 5,400 compromised small-business websites serving these fake checks.
That last point matters: the site you're on may be legitimate. Its owner just doesn't know someone slipped a script into it.
2) The page quietly fills your clipboard#
The moment you click the fake tickbox, a script copies a command to your clipboard. You don't see it happen. The page then shows the "verification steps." What you're about to paste isn't a code; it's something like a PowerShell or mshta command that reaches out to the attacker's server.
Some versions pad the command with a harmless-looking comment at the end, such as # I am not a robot - Cloudflare Verification ID: 4821, so that if you glance at the Run box, the visible tail of the line looks innocent.
3) You run it, so nothing looks suspicious#
When you press Enter, Windows (or macOS) runs the command with your permissions. To your computer, this looks like you deliberately ran a command, because you did. No exploit, no download prompt, no "this file may be dangerous" warning.
4) The real malware arrives#
The command fetches the actual payload. Most often that's an infostealer (Lumma, Vidar, StealC and similar), which grabs saved passwords, browser cookies, session tokens and crypto wallets within minutes. In other cases it's a remote access trojan that gives the attacker your screen, files, camera and microphone. A recent case we covered in our Week 40 roundup chained a paid Google ad, a fake ChatGPT page and a fake Cloudflare check into exactly that.
Why it works on careful people#
The usual advice - "don't click attachments," "check the sender" - doesn't apply here, which is exactly why fake CAPTCHAs took off.
- CAPTCHAs trained us to obey. We click "I'm not a robot" dozens of times a week without thinking. The scam sits inside a habit, not outside it.
- It shows up on sites you trust. A compromised blog, a recipe site, a supplier's homepage. The address bar is correct.
- The steps feel technical, which feels official. "Press Win+R" sounds like something IT support would say. Plenty of people have been talked through real fixes exactly like that.
- Nothing gets "downloaded." No file appears in Downloads, so the instincts built around suspicious attachments never fire.
- It's quick. Three keypresses, two seconds. Like smishing, it wins in the moment of autopilot, not in a test of knowledge.
The numbers: why fake CAPTCHAs are still a pain for businesses#
Fake CAPTCHA scams first went mainstream in 2024. Two years later, they haven't faded the way most tricks do. They've grown.
| Finding | Source |
|---|---|
| Fake-check "paste this" attacks were the most common initial access method seen by Microsoft Defender Experts, at 47% of cases | Microsoft Digital Defense Report 2025 |
| Detections rose 517% in the first half of 2025 | ESET Threat Report H1 2025 |
| Fake CAPTCHA detections rose another 108% from H2 2025 to H1 2026 | ESET Threat Report H1 2026 |
| These attacks made up 52% of Push Security's detections through Q2 2026, and 67% in August 2026 | Push Security |
| Seen in more than half of Vega's customer environments in Q2 2026 | Vega Threat Intel |
| 17,000+ infected URLs serving fake Cloudflare verification pages in one campaign | CTM360 via The Hacker News |
| 84 distinct command variations, using 20+ built-in Windows and Unix tools | Push Security |
ESET also notes that its own counts understate the problem, because a single attack shows up under several detection names across its stages.
Why business defences keep missing it#
It skips the email gateway. Most companies spent years and serious money filtering email. Fake CAPTCHAs mostly arrive through the browser, from search and compromised websites, so that investment never sees it. Even a well-run phishing simulation programme only trains the inbox reflex unless it's built to cover this.
It looks like the user did it. Security tools are built to spot malware forcing its way in. A command typed into the Run box by a logged-in employee looks like normal user activity, and the tools it calls (PowerShell, mshta, msiexec, curl) are signed parts of Windows that IT uses every day.
It changes faster than signatures. With dozens of command variants, heavy obfuscation and payload services generating thousands of unique variants, there's no single string to block. Some campaigns now store their configuration on public blockchains (a trick called EtherHiding), so there's no domain for anyone to take down.
One click becomes a company-wide incident. An infostealer on one laptop hands over that person's saved passwords and live session cookies. With a session cookie, attackers can walk straight into Microsoft 365 or other SaaS without triggering MFA - the same session-theft problem we covered in what actually breaks company security. From there, ransomware crews take over. Researchers have tied fake-check attacks to Qilin, Interlock, Termite and other ransomware operations, often via a remote-access tool installed on the first machine.
It's spreading to every platform and to cloud accounts. Mac users are now targeted with Terminal versions that drop macOS stealers, and some campaigns have added Linux. ESET also describes a newer variant that goes after company cloud accounts by tricking people into handing over sign-in tokens rather than running a command.
How to tell a real CAPTCHA from a fake one#
| Real check (Cloudflare, reCAPTCHA, hCaptcha) | Fake check (scam) | |
|---|---|---|
| What it asks | Tick a box, click images, or nothing at all | Press Win+R, Win+X, Cmd+Space, or open a program |
| Keyboard | Never needed | Ctrl+V and Enter are the whole point |
| Number of steps | One | A numbered list of two to four steps |
| Your clipboard | Untouched | Filled with a "code" you never copied |
| On failure | Shows another puzzle | Insists you "complete verification" to continue |
If you ever see the second column, close the tab. Don't try to "finish" the check to see what happens, and don't paste anything anywhere.
How to protect yourself at home#
- Learn the one sentence. No real website, CAPTCHA, error page or support chat will ever ask you to paste something into the Run box, PowerShell, Terminal or the File Explorer address bar. Teach it to family members too.
- On a Mac, update and respect the warning. macOS Tahoe 26.4 and later can block suspicious pastes into Terminal with a "Possible malware, Paste blocked" alert. The protection only works if you don't click "Paste Anyway." If you ever see that alert, the page that sent you there is the problem.
- Type addresses you care about instead of searching for them. Since most of these scams arrive from search results and ads, going straight to the real site removes most of the risk. Bookmarks are even better.
- Use an everyday account without admin rights. It won't stop every payload, but it limits what a pasted command can change.
- Don't keep passwords in the browser. Infostealers target browser-saved passwords and cookies first. A dedicated password manager, plus passkeys wherever a site offers them, means a stolen password file is worth far less. Passkeys can't be phished or replayed the way passwords and one-time codes can.
- Treat "install guides" with suspicion. If a guide for an app tells you to paste a command into Terminal, get the instructions from the developer's official site or documentation, not from a search result or ad.
How to protect a business#
Training matters, but fake CAPTCHAs are partly a configuration problem, and there are technical fixes most companies haven't applied.
1) Take away the easy paste targets#
Most fake-check lures rely on Win+R (Run) or Win+X (the power-user menu that opens Terminal). Blocking those two shortcuts for regular staff removes the most common route with little day-to-day disruption. One option is the per-user DisabledHotkeys value under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced (set to RX), deployed via Group Policy Preferences or Intune. This comparison of mitigations rates it as the best balance of protection and annoyance. Test it with your IT team first, and pair it with the controls below, since some versions use the File Explorer address bar instead.
2) Restrict what normal users can run#
Application control (AppLocker or Windows Defender Application Control) can stop standard users from launching tools they never need, such as mshta.exe, wscript.exe or cscript.exe, and can restrict PowerShell to Constrained Language Mode. Simply uninstalling PowerShell isn't a fix: payloads switch to cmd, curl, msiexec and other built-ins.
3) Watch for the tell-tale signs#
Commands typed into the Run box are stored in the registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. Make sure your EDR or SIEM alerts when PowerShell, mshta or curl is launched by Explorer with an internet address in the command line, or when a RunMRU entry contains one. Major security vendors now ship detection rules for this pattern; check that yours are switched on.
4) Make stolen sessions less valuable#
Assume an infostealer will eventually land somewhere. Phishing-resistant sign-in (passkeys or FIDO2 security keys), shorter session lifetimes for sensitive apps, conditional access tied to managed devices, and quick "sign out everywhere" procedures all shrink what one infected laptop is worth to an attacker.
5) Allow one remote-access tool, block the rest#
Fake-CAPTCHA intrusions often install a legitimate remote management (RMM) tool as a back door. If IT uses one RMM product, block every other one and alert when any appears.
6) Train for the real lure, not just email#
Show staff what the fake Cloudflare and reCAPTCHA screens actually look like, give them the one sentence, and make reporting easy and blame-free. Someone who reports "I pasted something weird" within five minutes is far more valuable than someone who stays quiet out of embarrassment.
"I already pasted it." What to do now#
If you ran the command, act quickly. Infostealers usually grab what they want within minutes, so speed beats perfection.
1) Disconnect the computer#
Turn off Wi-Fi or unplug the network cable. Don't shut down yet if it's a work machine - your IT team may want to see what's running.
2) If it's a work device, tell IT or security immediately#
This is not the time for embarrassment. Tell them what page you were on, roughly when, and what you were asked to do. That information is gold for the investigation. IT will usually isolate the machine, check what ran, and reset your sessions.
3) From a different, clean device, secure your accounts#
Start with your email, because it can reset everything else. Then your bank, password manager, work accounts, social media and any crypto wallets. For each one:
- Change the password.
- Use the "sign out of all devices" or "end all sessions" option. Changing a password alone doesn't always kill a stolen session cookie.
- Turn on or upgrade to passkeys or an authenticator app if you haven't already.
4) Move crypto immediately#
If you had a crypto wallet on that computer, assume its keys are compromised. From a clean device, move the funds to a new wallet with a new seed phrase.
5) Clean or reset the computer#
Running an antivirus scan is a start, but the cleanest fix after a confirmed infection is backing up your personal files and resetting or reinstalling the operating system. On a work device, leave this to IT.
6) Watch for follow-up fraud#
Keep an eye on bank statements, login alerts and "new device" emails for the next few weeks. Stolen data is often resold, so a second wave can come later.
Summary#
- Fake CAPTCHAs look exactly like Cloudflare, reCAPTCHA or hCaptcha checks, and they can appear on legitimate sites that have been hacked.
- A real CAPTCHA never asks you to use your keyboard. No Win+R, no Terminal, no Ctrl+V. If a "check" has steps, close the tab.
- The command you paste is the malware. It usually installs an infostealer that takes passwords, cookies and sessions within minutes.
- For businesses, fake CAPTCHAs are a top intrusion route because they skip email filters, looks like normal user activity, and leads straight to session theft and ransomware.
- Fix it with configuration, not just training: block Win+R and Win+X for staff, restrict scripting tools, alert on RunMRU and Explorer-launched PowerShell, and allow only one RMM tool.
- Make stolen credentials less useful: passkeys or FIDO2 keys, a password manager instead of browser-saved passwords, and short sessions on sensitive apps.
- If you pasted it: disconnect, tell IT, then from a clean device change passwords and sign out of all sessions, starting with your email.
Not sure whether your team would spot a fake Cloudflare check, or what one pasted command could reach inside your network? Get in touch - bluwarden runs phishing simulations and penetration tests that show you before an attacker does.
This article is general security guidance, not an assessment of your specific environment.
