Hackers Have Infected Over 5,400 Legitimate Websites With a Fake CAPTCHA Scam

Hackers Have Infected Over 5,400 Legitimate Websites With a Fake CAPTCHA Scam

Follow America's fastest-growing news aggregator, Spreely News, and stay informed. You can find all of our articles plus information from your favorite Conservative voices. 

Security researchers say attackers have compromised more than 5,400 websites belonging to over 2,200 organizations worldwide, using them to trick visitors into infecting their own computers with malware. The campaign, tracked by Netskope Threat Labs over the past several months, targets small businesses including clinics, plumbing companies and online stores.

Here’s how it works: you visit a real website you may already trust, and a CAPTCHA box appears. Instead of the usual click-a-box or pick-the-photos test, the page instructs you to open the Windows Run dialog and paste in a command. Following those instructions launches the attacker’s malware directly on your machine.

Remember this: a legitimate CAPTCHA never asks you to open Windows Run or paste a command into your computer. If a webpage tells you to do that, close it immediately.

How the sites got compromised

Where Netskope examined individual victims, most ran WordPress, with some running PrestaShop. Researchers still do not know how the attackers initially broke into these sites. Several hundred compromised sites can be active on any given day, and more than 300 have recently been contacting the attackers’ infrastructure each weekday.

The technique is known as ClickFix, and it works on psychology more than technical trickery. People are used to CAPTCHAs and routinely click through them without much thought. A familiar-looking verification screen on a legitimate site lowers your guard, and the malicious instructions get dressed up as just another step in the process.

Why this campaign is hard to shut down

What makes this operation unusual is where the attackers store their instructions: on the BNB Smart Chain test network, a blockchain developers normally use to experiment without spending real cryptocurrency. Instead of hosting malicious code on a regular server that investigators could get taken down, the attackers store it in a smart contract that the hacked websites check for their next set of instructions.

That setup gives the criminals cheap infrastructure that’s harder to dismantle through conventional means, and lets them update the attack across every compromised site at once without touching each one individually.

Netskope also found a newer, more advanced version of the attack that skips the fake CAPTCHA entirely. This variant uses WebRTC, the technology your browser normally uses for video calls, to open an encrypted connection to the attacker and pull down malicious code that can run without ever being saved as a file on your computer.

What you should do

  • If any website tells you to open Windows Run, PowerShell or Command Prompt, stop. Do not paste anything. Close the page.
  • A real CAPTCHA asks you to click a box or identify images. It never requires you to change settings or run commands.
  • Keep antivirus software updated with real-time protection enabled, and run a full scan if you think you followed suspicious instructions.
  • Only install updates through Windows Update or your browser’s own settings — never through a prompt on an unexpected webpage.
  • If you did follow a suspicious CAPTCHA’s instructions, disconnect the computer from the internet, run a full antivirus scan, then use a separate trusted device to change your passwords, starting with your main email account. Review active login sessions and turn on multifactor authentication wherever it’s available.

For website owners, Netskope recommends checking the integrity of CMS files, since researchers found malicious code injected into legitimate JavaScript files and hidden inside fake plugin directories. Keeping WordPress, PrestaShop and plugins updated, and removing unused plugins, are sound practices — though researchers have not tied this campaign to any specific known vulnerability.

The bottom line: a website should never need you to open Windows Run or paste a command to prove you’re human. If you see that request, close the page.

Share:

GET MORE STORIES LIKE THIS

IN YOUR INBOX!

Sign up for our daily email and get the stories everyone is talking about.

Discover more from Liberty One News

Subscribe now to keep reading and get access to the full archive.

Continue reading