A new scam is making the rounds, and it’s especially dangerous because it doesn’t always look like phishing. Sometimes it starts with a fake Zoom or Teams invitation. Other times, it starts with something as ordinary as a Google search. In both cases, the victim lands on a webpage that looks legitimate and sees what appears to be a familiar “I’m not a robot” or CAPTCHA verification.
Then the page gives instructions like: Press Windows + R, then Ctrl + V, then Enter to verify you’re human.
That is not a real verification step. It’s a cyberattack.
The technique is commonly called ClickFix. The malicious webpage quietly places a command onto the computer’s clipboard. The victim is then instructed to paste that command into Windows and run it. To the user, it may look like they are completing a normal security check. In reality, they may be launching malware or giving an attacker remote access to the computer. The scary part is what happens next. Sometimes, nothing obvious happens at all. A window may flash for a second, the webpage may load normally, and the employee may continue working and assume everything is fine. Meanwhile, an attacker may already have access to the computer.
One reason ClickFix attacks are so effective is that there isn’t just one way to encounter them. A phishing email may look like a normal Zoom, Microsoft Teams, DocuSign or calendar notification. The link leads to a convincing webpage that asks the user to complete a “human verification” before joining the meeting or opening the document. Because meeting invitations and account notifications are part of everyday work, the request may not immediately seem suspicious. ClickFix can also appear through normal web browsing. Someone may search Google for a legitimate work topic, click a regular search result and land on what appears to be a normal article, technical resource or business website. Before displaying the content, the site presents a fake CAPTCHA and asks the visitor to run the Windows command.
Attackers may create malicious websites specifically for this purpose, or legitimate websites can sometimes be compromised and used to distribute the attack. That means a link doesn’t have to come from a suspicious email to be dangerous.
Most people have been trained to watch for suspicious attachments and downloads. ClickFix attacks work differently. Instead of directly installing something on the computer, the attacker convinces the user to execute the malicious command themselves. That can help the attack bypass some traditional security controls and makes it harder for the victim to recognize what just happened. There may be no scary warning message, obvious download or suspicious-looking program. The webpage may simply continue loading as though everything worked normally.
There is one rule worth remembering: No legitimate website should ever ask you to paste commands into Windows to prove you’re human.
Real CAPTCHA and verification tools happen inside your browser. They may ask you to check a box, select certain pictures, solve a simple puzzle or confirm that you’re not a robot. They should not ask you to press Windows + R, open PowerShell, open Command Prompt, open Terminal, paste something into Windows or run a command to continue. If you see instructions like that, close the tab immediately.
We tend to trust Google search results because they feel less risky than links inside unsolicited emails. That trust can be exploited. Attackers can create pages designed to appear in search results, and legitimate websites can also be compromised. Be especially careful when you land on an unfamiliar website, even if you reached it through a normal search. If the page suddenly asks you to perform an unusual action outside your browser, stop.
One of the most dangerous parts of this attack is how uneventful it can feel. You might follow the instructions, see a quick flash on the screen and then get the article or webpage you expected. That can create the impression that everything worked properly. But if you followed unusual keyboard instructions or pasted something into Windows, contact your IT team even if the computer seems fine. A lack of visible symptoms does not mean nothing happened.
Be suspicious of any website that says things like “Press these keys to verify,” “Run this command to continue,” “Paste this to fix a display problem” or “Open Windows Run to update your browser.” Normal websites do not need access to Windows Run, PowerShell or Command Prompt to display a webpage.
Modern cybersecurity software may automatically isolate a computer from the network if it detects suspicious activity. To the employee, that can simply look like the internet suddenly stopped working. If your computer loses connectivity or starts behaving strangely immediately after you clicked a link, visited an unusual website or followed suspicious instructions, tell your IT provider exactly what happened. That context matters.
Tell your IT team immediately. Minutes matter during a security incident. Disconnect the computer from the network by turning off Wi-Fi or unplugging the Ethernet cable, stop using the computer, and don’t try to investigate or fix it yourself. Tell IT exactly what you clicked and what instructions you followed. And don’t stay quiet because you’re embarrassed. These attacks are designed to fool people who are simply trying to do their jobs. Reporting something quickly gives your security team the best chance to contain the problem. We would much rather investigate a false alarm than discover a real compromise hours later.
A website that asks you to copy, paste and run something on your computer should be treated as malicious. CAPTCHAs happen inside your browser. They do not require Windows Run, PowerShell, Command Prompt or pasted commands.
If something feels unusual, stop before clicking or following the instructions. And if you’re not sure, ask your IT provider first. That’s what we’re here for.