A fake CAPTCHA can look like a routine security check, especially when it copies the colors, logos, and wording used by a familiar service. The dangerous version does more than ask you to click a box or identify images. It tells you to open Windows Run or macOS Terminal, paste text, and execute it. That is not a normal human verification step. It is a social engineering trap.
Microsoft calls this technique ClickFix. The page creates a small technical problem, offers a supposed fix, and relies on the visitor to run the final step. Some campaigns deliver information stealers, remote access tools, or other malware. Stop when a website asks you to use a system shell, then verify the page through a trusted source.
Quick answer
A real CAPTCHA keeps the check inside the webpage. It may ask you to select images, type visible characters, or confirm that you are human through a browser control. It should not ask you to open Run or Terminal, paste a command, disable security software, or install an extension. Those instructions are strong signs of a fake CAPTCHA attack. If you already ran the command, stop entering passwords on that device, scan it with trusted security tools, and secure your accounts from a clean device.
How the fake CAPTCHA trap works
The attack can begin with a malicious advertisement, a compromised website, a phishing message, or a search result. The page may imitate a browser warning, a Cloudflare-style check, a video player error, or a message saying that your browser needs repair.
The design is meant to reduce hesitation. A familiar logo, countdown, or warning about unusual traffic makes the request feel like part of the normal process. The page may first show a checkbox or loading animation. It then moves the task outside the browser.
In a common ClickFix flow, the page places text on the clipboard and tells you to open the Windows Run dialog. It asks you to paste and run the text. Related campaigns can direct macOS users to paste commands into Terminal. The exact text changes, but the pattern stays the same: the webpage asks the visitor to become the execution step.
A browser can display a message, request permission, or send you to a legitimate sign-in page. It does not need you to run an arbitrary operating system command to prove that you are human. A request to do so is a security warning, even if the page looks polished.

What real CAPTCHA checks do not ask you to do
CAPTCHA systems vary. Some run in the background, while others ask you to select objects, solve a challenge, or confirm a checkbox. The details differ, but the check stays within the browser and follows the site's normal navigation.

Be suspicious when the page asks you to:
- Open Windows Run, PowerShell, Command Prompt, macOS Terminal, or another system tool.
- Paste text that you did not write or cannot read into a system window.
- Run a command to prove that you are not a bot.
- Install a browser extension or application to complete a basic CAPTCHA.
- Turn off antivirus protection, ignore a browser warning, or continue after an error.
A real CAPTCHA may fail because of network reputation, browser settings, or accessibility issues. Reload the known website, use its official support page, or try a different browser. Do not execute text supplied by an unknown page. For context about the signals a site can collect during a visit, see what websites can collect during a visit.
Why the command is the dangerous part
The command gives the attacker a capability that the webpage alone may not have. It can call a built-in system utility, download a script, launch another process, or connect to an attacker-controlled server. Microsoft has documented ClickFix campaigns that abuse trusted tools and use obfuscated scripts to deliver later stages.
This also explains the clipboard step. Long or confusing text becomes easier to execute and harder for a hurried user to inspect. A command that looks like a repair action can still fetch code from the internet and run it with your permissions.
The result is not always the same. One campaign may deliver an infostealer, another may install a remote access tool, and another may fail because a security product blocks the payload. A failed visible download does not prove that the device is clean. If you ran an unknown command, treat the event as a possible compromise.
What infostealers and other payloads may target
An infostealer is malware designed to collect information from a device and send it to an attacker. Microsoft reports that ClickFix campaigns have delivered infostealers such as Lumma Stealer, along with remote access tools and loaders. The final payload and its collection rules can change.
Depending on the malware, targets can include:
- Saved usernames and passwords in supported browsers.
- Browser cookies and other session data that may help an attacker reuse a login.
- Autofill information, browsing data, and browser extension data.
- Cryptocurrency wallet files, email client data, VPN settings, or developer credentials.
- Device information such as the operating system, installed applications, and hardware details.
The danger is not limited to the account you were using when the fake CAPTCHA appeared. A stealer can search local browser profiles and application files. If the device contains personal and work accounts, the exposure may extend beyond the original website.
Do not assume that a password change fixes every stolen session. Change passwords from a clean device, enable multifactor authentication, and sign out other sessions when the service provides that option. If financial information or a cryptocurrency wallet may have been exposed, contact the provider through its official website.
ClickFix versus CrashFix
ClickFix describes the broader social engineering pattern: a page presents a problem and persuades the user to copy, paste, and run a command as the solution. It has appeared in fake CAPTCHA checks, browser errors, software installation lures, and other forms.
CrashFix is a related variation documented by Microsoft in January 2026. In the campaign Microsoft analyzed, a malicious browser extension caused browser problems and then displayed a fake security warning that encouraged the victim to execute a command. That does not mean every browser crash is CrashFix. The useful lesson is that a browser problem followed by instructions to use Run or Terminal deserves suspicion.
What to do if you already followed the instructions
Act as if the device may be compromised until a trusted scan and, when necessary, professional review show otherwise. Do not keep testing the page or repeat the command to see what it does.
1. Stop entering sensitive information
Do not sign in to banking, email, shopping, work, or social accounts from the affected device. The FTC recommends stopping activities that require passwords or personal information when malware is suspected. If the device belongs to an employer or school, contact its security or IT team before deleting files.
2. Disconnect when active compromise is suspected
If the device is still showing unusual activity or you suspect that malware is communicating with an attacker, disconnect it from Wi-Fi or wired networking if you can do so safely. Do not plug in external drives or copy sensitive files from the device. Isolation can limit ongoing communication, but it does not remove malware.
3. Scan with trusted security software
Update your security software through its official interface and run a full scan. On Windows, Microsoft Defender Offline can restart the computer and scan from a trusted environment outside the normal Windows kernel. If the scan finds a threat, follow the product's removal guidance and keep the detection record.
4. Secure accounts from a clean device
Use a different device that you trust to change important passwords. Start with email, financial services, password managers, work accounts, and any account that was open in the browser. Use unique passwords and enable multifactor authentication. Review recent sign-ins and revoke unfamiliar sessions. Contact financial institutions quickly if payment data may have been exposed.
5. Get help when the stakes are high
A confirmed stealer, a work computer, a cryptocurrency wallet, or a system with important files may need specialist help. If you cannot confirm that the device is clean, consider a full rebuild with professional guidance. Do not download a random cleanup tool from a pop-up, because fake security software is another malware lure.

How to avoid the trap next time
Treat every request to leave the browser as a separate security decision. Check the address bar before interacting with a verification page, especially after an advertisement or unexpected redirect. If the domain is unfamiliar, close the tab and reach the service through a bookmark or an address you already trust.
- Never paste unknown text into Run, PowerShell, Command Prompt, Terminal, or a browser developer console.
- Do not install an extension because a page says that your browser is broken.
- Keep the operating system, browser, and security software updated.
- Use multifactor authentication so a stolen password is harder to use by itself.
- If a page pressures you with a timer or threatens immediate account loss, pause and verify the request elsewhere.
The warning sign is the action the page wants, not how professional the page looks. When a supposed CAPTCHA asks you to run code, close the page.
Frequently asked questions
Can a real CAPTCHA ask me to open Windows Run?
No. A real CAPTCHA may use a checkbox, image selection, text entry, or an invisible browser check. It should not require you to open a system shell and run text supplied by a webpage.
Can a fake CAPTCHA steal data without the command being run?
A suspicious page can collect normal browser and network information, but the ClickFix infection chain usually depends on persuading the user to execute the supplied command. Do not rely on that distinction as a safety test. Close the page, avoid downloads, and scan the device if you opened files or ran anything.
What is the first step after running the command?
Stop using the device for passwords and sensitive activity. If it appears compromised, isolate it, scan it with trusted security software, and change important passwords from a clean device. For work devices, financial accounts, or cryptocurrency wallets, contact the relevant security or fraud team promptly.
A simple rule to remember
A CAPTCHA asks you to interact with a webpage. It does not ask you to run a command. ClickFix works by making that boundary feel ordinary, then using your own action to start the infection. If a page asks you to open Run or Terminal, stop, close the page, and verify the service through a trusted route. If you already followed the instructions, treat the device and its saved sessions as potentially exposed until you scan it and secure the accounts from somewhere clean.
