Over 5,400 legitimate websites have been compromised to deliver fake CAPTCHA scams that trick users into installing malware through a method known as ClickFix.
In a troubling development, security researchers have discovered that over 5,400 legitimate websites are now serving fake CAPTCHA prompts designed to trick users into executing malware commands via the Windows Run dialog. This alarming trend has been identified as part of a broader campaign that targets unsuspecting visitors to small business websites.
Imagine visiting the website of a local business you trust, only to be confronted with a CAPTCHA that appears routine. However, this CAPTCHA instructs you to open Windows Run and paste a command. Such prompts should raise immediate red flags, as they are not typical behavior for legitimate CAPTCHAs.
According to Netskope Threat Labs, which has been monitoring this issue, the scale of the campaign is significant, affecting more than 2,200 organizations worldwide. The compromised sites include a diverse range of businesses, from clinics and plumbing companies to online retailers. Most of these websites are built on platforms like WordPress and PrestaShop, although the exact methods of initial compromise remain unclear.
Researchers have noted that several hundred of these compromised sites can be active on any given day, with over 300 sites reportedly contacting malicious infrastructure during weekdays. The attack begins with malicious code embedded in a compromised website. When a user visits such a site, the code can trigger another script that blurs the page and presents a CAPTCHA-like prompt.
Unlike standard CAPTCHAs, which typically ask users to verify their humanity through simple tasks, these malicious prompts instruct users to execute potentially harmful commands. This technique, known as ClickFix, exploits users’ familiarity with CAPTCHAs, making them more likely to comply with the dangerous instructions.
Cybercriminals have previously employed similar tactics, such as fake Windows update screens, to manipulate users into executing harmful actions. The underlying psychology of these scams relies on the assumption that users will let their guard down when faced with a familiar interface.
What sets this campaign apart is the attackers’ use of the BNB Smart Chain test network to store instructions for the compromised websites. This method provides a more resilient infrastructure for the criminals, as traditional web servers can be shut down once discovered. In contrast, the blockchain allows for easier updates to the malicious code without needing to modify each hacked site individually.
Netskope has also identified a newer variant of the attack that bypasses the fake CAPTCHA entirely. This version utilizes WebRTC technology, typically used for real-time communications, to create an encrypted connection with the attacker. This allows the attackers to deliver additional malicious code directly through the browser, circumventing traditional file-saving methods.
For users, the technical details may be less critical than the overarching message: if a website instructs you to open Windows Run, PowerShell, or Command Prompt, you should stop immediately. Do not follow any instructions to paste commands or execute actions outside the browser. Instead, close the page and protect your device.
Standard CAPTCHAs should only require you to click a checkbox or identify images; they should never prompt you to alter settings or run commands on your computer. Maintaining strong antivirus protection is also essential. Ensure your antivirus software is up to date and has real-time protection enabled. If you inadvertently follow suspicious instructions, disconnect from the internet and run a full system scan.
Website owners must take this threat seriously as well. Netskope advises regularly checking the integrity of content management system files. Malicious code can be hidden within legitimate JavaScript files or fake plugin directories. Keeping platforms like WordPress and PrestaShop updated, as well as removing unnecessary plugins, is crucial for maintaining security.
While researchers have not pinpointed the exact vulnerabilities that allowed attackers to compromise these websites, following best security practices can help mitigate risks. The deceptive nature of these attacks highlights the importance of vigilance when browsing the web, especially on sites you may trust.
Ultimately, the best defense against these types of scams is awareness. A legitimate website should never require you to open Windows Run or paste commands to verify your identity. If you encounter such a request, close the page immediately. This simple precaution could save you from inadvertently installing malware.
Would you recognize a fake CAPTCHA if it appeared on a website you trusted? Share your thoughts with us at CyberGuy.com.
According to Netskope Threat Labs, the best approach to staying safe online is to remain cautious and informed about potential threats.

