That “I’m Not a Robot” Check Could Be Installing Malware
By Jim McMahonon 10/07/2026 |
![{$insert['content_title']](/content/file/6473_amihuman.jpg
)
Most of us have clicked enough "I'm not a robot" boxes that we barely think about them anymore. You want to read a page, the website wants to check that you are human, and everyone gets on with their day.
Criminals are counting on that routine.
New reporting from The Hacker News describes a campaign involving more than 100 compromised websites displaying fake Cloudflare verification pages. Instead of simply checking a box, visitors are instructed to run a command that downloads and installs malware called LunexStealer.
If a human verification page asks you to open Windows Run and paste a command, close the page.
Proving you are human should not require running software on your computer.
What Is Happening?
According to the reporting, Ukraine's computer emergency response team, CERT-UA, published an advisory about the campaign on September 30, following activity observed that month. Attackers injected malicious code into websites to show visitors a convincing verification screen.
The technique is known as ClickFix. Microsoft explains that attackers disguise malicious commands as steps needed to fix an error or complete a security check. A page might tell you to press Windows+R, paste something from your clipboard, and press Enter. Some versions copy the command to your clipboard when you click a button, so you never deliberately copy a suspicious-looking line of code.
The trick is to make you do the dangerous part yourself. You think you are completing a verification. Windows receives an instruction to run something.
A Familiar Website Can Still Show a Fake Check
One important detail is that this campaign reportedly involves compromised websites. You do not necessarily have to wander onto an obviously shady page to encounter the trap.
A familiar address, a professional-looking page, or a recognizable logo does not make a request to execute a command safe. Cloudflare's branding is being impersonated. That does not mean Cloudflare itself was breached or that its legitimate verification service installs malware.
The question to ask is simple: Why does this website need me to run a command on my PC just to read it?
Ask that before pressing Enter.
We Have Trained People to Expect More Security Hoops
Think about what we already ask people to do online. Remember a password, enter a PIN, approve a two-factor authentication request, and identify motorcycles in a grid of pictures that keeps changing. Sometimes you complete one check only to get another.
With all that going on, I can see someone looking at this fake verification and thinking, "Well, I guess this is how they do it now."
That does not make someone stupid. It makes the scam convincing. People have become accustomed to unfamiliar security steps standing between them and whatever they are trying to accomplish. Criminals take advantage of that expectation by making dangerous instructions look like just another requirement.
But there is a clear stopping point.
A human verification check should not ask you to open Windows Run, PowerShell, or Terminal and execute a command.
How to Recognize the Trap
Watch for these three requests:
- Open Windows Run, PowerShell, Terminal, or Command Prompt to complete a verification.
- Paste clipboard content and execute it without understanding what it does.
- Install software or disable security protection to prove you are human.
Those are reasons to stop. Close the tab instead of trying to finish the process. If the page copied something to your clipboard, replace it by copying a harmless word before you accidentally paste it elsewhere.
There is no prize for being the most cooperative person on a suspicious website.
Can Antivirus Software Help?
Yes. Antivirus software with web and phishing protection can help block parts of this attack.
At MajorGeeks, we have recommended Bitdefender Antivirus Free and Avast Free Antivirus partly because of their anti-phishing capabilities. These protections may block a known malicious page before you reach it or stop a connection to the server delivering the malware. If you do run the command, malware detection and behavior monitoring provide another opportunity to catch the attack.
The key word is may. A newly compromised website or a changed payload can escape detection. We have not tested either product against this particular campaign, so we cannot say that it will stop it.
Keep your security software updated and its web protection enabled. If it blocks a verification page, do not disable it because the page insists the warning is a mistake. If no warning appears, that still does not make the instructions safe.
What If You Already Followed the Instructions?
Seeing the page is different from executing its command. If you closed it without running anything, you have not completed the malware installation step described here.
If you did execute the command, treat the computer as potentially compromised. Disconnect it from the network and contact your IT department if it is a work or school device.
For a personal PC, run security scans using updated tools. Malwarebytes is available on MajorGeeks as an additional scanning option. However, removing malware does not undo information theft, and a clean scan cannot prove that your account information was never stolen.
From another trusted device, change important passwords, starting with your email account. Use account security settings to sign out other sessions, and enable multifactor authentication where available. If an attacker stole an active login session, changing a password alone may not be enough.
The Geek Verdict
The useful lesson is easier to remember than the malware's name: a CAPTCHA should never require you to paste and execute a command.
We have become accustomed to jumping through little hoops to use the internet. Attackers are capitalizing on using one more hoop and hoping we follow the instructions without thinking. Checking a box. Click a box. That's OK. Giving a website the ability to run software on your computer is quite another. Don;t fall for it.
|
Jim McMahon
Jim McMahon, aka Corporal Punishment, is the founder of MajorGeeks.com. He has spent decades testing software, troubleshooting Windows, and helping users cut through the nonsense. He loves real freeware, hates bloatware, and runs on caffeine, sarcasm, and questionable choices. |
comments powered by Disqus




