A fake “prove you’re human” box on your screen could be the first step in someone stealing your bank passwords and crypto wallet.
Quick Take
- Scammers now build fake CAPTCHA pages that look like the real thing but trick people into running hidden malware.
- The Federal Trade Commission (FTC) says the scam asks victims to press “Windows + R,” then “Ctrl + V,” then “Enter.”
- Those keystrokes secretly paste and run malicious code that steals passwords, banking logins, and crypto wallet data.
- Security experts, universities, and consumer watchdogs across the country are all warning about the same pattern.
- A real CAPTCHA never asks you to download files, copy commands, or open a “Run” box.
A Familiar Test Turned Into a Trap
Millions of people click “I’m not a robot” boxes every day without thinking twice. That trust is exactly what scammers are now exploiting. A new wave of fake CAPTCHA pages mimics the normal verification screen but adds a strange extra step, asking users to run commands most people would never think to question.
The Federal Trade Commission (FTC) laid out the exact pattern in a June 2026 consumer alert. Victims see an unexpected CAPTCHA request, then get told to press “Windows + R,” paste something with “Ctrl + V,” and hit “Enter.” The agency warns this sequence lets scammers “paste and run hidden malware” directly onto a person’s device.
How the Hidden Malware Actually Works
The trick relies on a person’s own hands to do the damage. Malicious code on the fake page secretly copies a command to the clipboard the moment the page loads. The victim never sees what got copied. They just follow instructions that seem harmless, and the malware quietly installs itself in the background.
Once installed, the software can dig through a device for saved passwords, browser cookies, and login details for email and banking apps. Cybersecurity researchers have tied versions of this attack to information-stealing programs, including one called Lumma Stealer, which specifically targets cryptocurrency wallets and other financial accounts stored on a computer.
Warnings Are Piling Up From Multiple Directions
This is not a one-off story from a single news outlet. University security teams, local governments, and national consumer protection groups are all sounding the same alarm. Duke University’s security office says threat actors are spreading the malware through “fake CAPTCHA tests and social media” to get people to run harmful code themselves.
The city of Roseville, California, issued its own public notice describing the same bait-and-switch setup, warning residents that a “fake CAPTCHA” scam is spreading and designed to install hidden malware and steal personal information. When separate institutions, from federal regulators to city governments to university IT departments, describe the identical attack chain, it signals a coordinated criminal effort rather than isolated incidents.
The Simple Rule That Protects You
Security experts agree on one clear line of defense. A legitimate CAPTCHA only asks a person to click a box or solve a simple picture puzzle. It never asks anyone to open a command window, paste anything, or press “Enter” to prove they are human. Malwarebytes puts it plainly: “You shouldn’t be asked to download files or paste commands”.
If a CAPTCHA prompt does ask for those steps, the safest move is to close the browser tab immediately and avoid typing anything. Anyone who already followed the instructions should run a full antivirus scan and change passwords for sensitive accounts right away, since stolen credentials can be used within minutes of an infection.
This scam also fits a bigger pattern worth watching. Everyday people are being asked to place more trust in digital systems, from banking apps to government logins, even as the tools meant to protect that trust get turned against them. That gap between convenience and safety is one more reason people across the political spectrum feel like ordinary citizens are left to fend for themselves against fast-moving fraud.
Sources:
youtube.com, consumer.ftc.gov, roseville.ca.gov, trendmicro.com













