The fake CAPTCHA scam that hijacks your computer
You are reading an article, watching something, or chasing a download, and a box pops up that looks like the security checks you see every day. The “verify you are human” kind. Except this one does not ask you to click pictures of buses. It tells you to press Windows + R, then Ctrl + V, then Enter. Follow those three steps and you are not proving anything. You are pasting a hidden command and running it yourself, and that command installs malware on your own computer.
The FTC flagged this one in June 2026, and it is spreading fast for a simple reason: it is built to look exactly like a routine safety step, so the victim is the one who installs it. If you already did it, that is not carelessness. It is a well-made trick. What matters now is moving quickly.
How to recognize it
A real CAPTCHA never asks you to touch keyboard shortcuts or paste anything. It asks you to click images, tick a box, or type characters you can actually see on the screen. The moment a “verification” tells you to press Windows + R, which opens a Run command box, or to paste something and hit Enter, stop. That key sequence drops a hidden command, usually a PowerShell script, into your computer and runs it. No legitimate website can or will ask you to do that.
If you already followed the steps
Disconnect from the internet right away by turning off Wi-Fi or unplugging the cable. The payload in these campaigns is usually an information stealer that scrapes saved passwords, browser cookies, and crypto wallet data, so the faster you cut it off, the less it can send out. Then, from a different device, change the passwords on your email, your bank, and any crypto or financial accounts, and switch on two-factor authentication. Run a full scan with your security software, and if you cannot be sure the machine is clean, treat it as compromised and have it reset or professionally checked. This is the same situation as giving a scammer remote access to your computer, and the cleanup is the same.
Save what you saw, then report it
Before you close everything, screenshot the page and note which website you were on when it appeared. These prompts usually ride on hacked sites or sketchy streaming and download pages, and that detail helps later. Our guide to preserving evidence in the first 24 hours covers how to capture it cleanly. Then report it at ReportFraud.ftc.gov and IC3.gov. If passwords or financial details may have been taken, IdentityTheft.gov walks you through locking things down step by step.
Why this one works
It flips the usual script. You have been trained to ignore “click this link” warnings, so an attacker stopped sending links. Instead it asks for a few keystrokes that feel like a normal security step, and that small change is enough to get past instincts that would otherwise catch it. The defense is just as simple. No real human-verification check ever uses Windows + R or asks you to paste a command. If one does, it is not a CAPTCHA. Close the tab.
— Gus