We’ve all become accustomed to CAPTCHA verification prompts online.
Click the box that says “I’m not a robot.” Select the pictures containing traffic lights. Complete a puzzle. Then continue to the website.
Cybercriminals know how familiar these verification screens have become—and they’re taking advantage of that trust.
A growing phishing and malware technique uses fake CAPTCHA pages that look like legitimate security checks but provide unusual instructions designed to trick you into running malicious commands on your own computer.
Instead of asking you to identify an image or click a checkbox, the fake CAPTCHA may tell you to:
If a website asks you to do this, stop. Do not follow the instructions.
One of the challenges cybercriminals face is getting malicious software onto a computer.
Modern operating systems, web browsers, antivirus software, and endpoint security products contain protections designed to prevent websites from simply installing programs without permission.
So attackers have found another approach:
Convince the user to run the malicious command for them.
A fake CAPTCHA creates the illusion that you're simply completing another routine security verification.
Behind the scenes, however, the website may have copied a command to your clipboard. When you follow its instructions and paste that content into Windows Run, PowerShell, Terminal, or another command interface, you could be instructing your computer to download or execute malicious software.
And because you initiated the command yourself, the attack may have a better chance of bypassing some of the protections designed to prevent unauthorized activity.
Fake CAPTCHA pages can look surprisingly convincing.
They may use familiar colors, checkboxes, verification messages, and instructions such as:
“Complete these verification steps.”
The warning sign isn't necessarily how the page looks. It's what the page asks you to do.
For example, a fake CAPTCHA targeting a Windows computer might tell you to press the Windows Key + R, paste something, and press Enter.
A version targeting a Mac might instruct you to open Terminal, paste a command, and press Enter.
Those aren't normal CAPTCHA verification steps.
A legitimate CAPTCHA should never require you to open Terminal, PowerShell, Command Prompt, or the Windows Run dialog and paste or execute a command.
If a website asks you to do that, assume something is wrong.
The command being pasted may look like meaningless technical text, or you may not see exactly what it is doing.
Depending on the attack, executing it could potentially install malware designed to steal information from your computer, including saved browser credentials, session cookies, financial information, business data, or other sensitive information.
It could also give an attacker an initial foothold that can be used for additional malicious activity.
This is one reason these attacks can be particularly dangerous for businesses. One employee following what appears to be an innocent verification prompt could potentially put company information or systems at risk.
If a CAPTCHA or verification screen asks you to open another program on your computer, don't continue with the instructions.
Close the webpage instead.
If you already copied something but didn't paste and execute it, simply copying the text generally isn't the dangerous part. The critical step is executing the command.
If you did paste the command and press Enter, contact your IT provider or security team immediately.
Don't wait to see whether something unusual happens. Malware is specifically designed to operate without attracting attention, and the sooner your IT team can investigate the device, the better.
Technology plays a major role in protecting your organization, but attackers increasingly look for ways to convince employees to bypass those protections themselves.
Fake CAPTCHA attacks are a good example.
The employee isn't intentionally downloading malware. They believe they're following instructions necessary to access a website.
That's why cybersecurity awareness isn't just about telling employees “don't click suspicious links.” Today's attacks require employees to recognize when a seemingly legitimate website asks them to perform an action that doesn't make sense.
A useful rule to share throughout your organization is:
If a website asks you to open a command window, paste something, or run a command to prove you're human, stop and contact IT.
Taking an extra minute to ask whether something is legitimate can prevent a much larger security incident.
Cybercriminals continually change their techniques, which means the protections that worked several years ago may not be enough today.
A strong cybersecurity strategy should combine appropriate endpoint protection, email and web security, identity protection, patching, monitoring, backups, and ongoing employee security awareness.
If you're unsure whether your current technology and cybersecurity protections are keeping pace with today's threats, schedule a discovery call with A M Exclusive.
We'll learn more about your organization, your current IT environment, and your concerns to determine whether a complimentary technology assessment makes sense for your business.