Cybercriminals are using convincing fake Captchas to trick users into installing malware. These malicious Captchas imitate legitimate verification checks but instruct users to perform actions that can compromise their computers.
Instead of typical Captcha tasks like ticking a box or solving a puzzle within the browser, fake versions ask users to use keyboard shortcuts or paste commands into their computer. For example, users might be told to press Windows key + R to open Windows Run and then paste text.
If users follow these instructions, they could unknowingly run a command that downloads malware. Malware can then be used to steal passwords and personal information. These scams can appear on legitimate websites that have been compromised by cybercriminals.
Warning signs of a fake Captcha include being asked to open another program, use a keyboard shortcut to access a Windows tool, or copy and paste text or code. If these instructions are given, users should close the browser tab.
If instructions have been followed and a command run, the computer should be treated as potentially compromised. Users are advised to disconnect from the internet, run a malware scan, avoid signing into important accounts, and change passwords on another trusted device.