Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

Malicious Captchas are on the rise

Posted on May 3, 2025May 3, 2025 by Martin Brinkmann

Captchas can be quite annoying, especially if your input is not accepted or if they do not work at all. You may now add malicious captchas to the list of annoyances.

Proton Mail published one example on X recently.

Fake CAPTCHA attacks are on the rise, causing many to fall prey to infostealers injecting malware onto their devices.

Here's how it works, and what you can do to stay safe

๐Ÿ‘‡๐Ÿงต 1/7 pic.twitter.com/gjwIf2YPnl

— Proton Mail (@ProtonMail) May 2, 2025

The malicious captcha tries to convince unsuspecting users to run a command on their Windows machines.

Here is how it works:

  1. The victim lands on a page with the fake captcha, for instance after clicking on a link in an email or chat.
  2. The captcha displays the usual “I’m not a robot” button.
  3. A click or tap on the button copies a PowerShell command to the operating system’s clipboard.
  4. Victim is instructed to use the shortcut Windows-R to open a run box.
  5. Asked to use Ctrl-V to paste the command and to press Enter to execute it.

Doing so downloads malware from a server on the Internet and runs it on the user’s system. This can be infostealers, malicious software that steals personal information, such as logins, financial documents, or photos.

While most, or even all, experienced users may never fall for that, it is almost a given that inexperienced users may. They may have difficulties getting the run box to open or paste the command, but they probably do not suspect foul play.

How to protect yourself

Protection is quite easy.

No legitimate captcha will ever ask you to execute a command on a local system, or to download a file and run it.

That is pretty much all that you need to protect yourself and your data against this type of attack.

Clearly, you may also want to ask yourself whether you trust the site you are on. Even if you conclude that you do, you should not run anything on the local computer when prompted to do so by a captcha.

Now You: how do you handle captchas on the Internet?

Tags:
Category: Security & Privacy

Post navigation

โ† Expect more ads in AI chats soon, courtesy of Google
Crapfixer for Windows review โ†’

3 thoughts on “Malicious Captchas are on the rise”

  1. Tom Hawack says:
    May 3, 2025 at 11:47 am

    I boycott any Website requiring a Captcha which requires user input.
    I accept Captchas of the sort ‘Verify you are human’ because it only requires a click.

    Google Captchas are always blocked in conformity with my policy regarding Google.
    Cloudflare Challenge Captchas are accepted given I’ve never encountered any requiring more than a user click. Bothering only when you wipe out site cookies when exiting the site as I do given most Captchas if not all set a session-only cookie which may be valid for an idiotic 10 minutes (Yep, as with Kagi Translate without an account) up to the whole session.

    Regarding these new malicious Captchas, great you point this out Martin, as well as stating that “No legitimate captcha will ever ask you to execute a command on a local system, or to download a file and run it.”.

    Reply
    1. Andy Prough says:
      May 3, 2025 at 7:05 pm

      I’m the same on all points Tom, I block all Google Captchas since I’m already blocking everything from Google, and anything else that requires more than a click is not worth the bother. I also delete cookies when exiting sites. These new malicious Captchas sound weird – why would I ever run a command on my computer to look at a website? But, I guess some users are uninformed enough to do just about anything.

      Reply
    2. Tom Hawack says:
      May 7, 2025 at 4:00 pm

      For the sake of truth I have to update my above comment. Update, not rectify :

      “(…) most Captchas if not all set a session-only cookie which may be valid for an idiotic 10 minutes (Yep, as with Kagi Translate without an account) up to the whole session.”

      Kagi Translate now sets the Cloudflare Challenge Captcha validity for the whole session. Previously it’d be only for 10 minutes and even worse : Captcha would reload as soon as the user moved to another tab (I had to include the site to a ‘Disable Page Visibility API’ userscript I use on specific sites). The change is conform to sanity ๐Ÿ™‚

      Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • May 18, 2025 by Martin Brinkmann Netflix to use AI "to serve the right ad to the right member at the right time"
  • May 17, 2025 by Martin Brinkmann Windows 10 update may cause another Bitlocker recovery reboot issue
  • May 15, 2025 by Martin Brinkmann Chrome 136 update patches security issue that is exploited in the wild
  • May 13, 2025 by Martin Brinkmann Firefox 138.0.3 fixes two crashes and some other issues
  • May 12, 2025 by Martin Brinkmann Microsoft 365: Windows 10 continues to be supported, at least somewhat

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2025 Chipp.in Tech News and Reviews