When 'prove you're human' is the trap

You click a link, or a download, and a familiar-looking page appears: a box to tick, a Cloudflare or Google logo, verifying you are human. You’ve cleared a thousand of them. But this one is chattier. It asks you to do a few small things to confirm — press the Windows key and R, then Ctrl and V, then Enter. Harmless-looking. Routine, even.

It is not routine. Those keystrokes prove nothing about you. They open a hidden command line and paste in an instruction the page copied onto your clipboard the moment you clicked — an instruction to fetch and run malware. Follow the steps and you’ve installed it yourself, by hand, believing you were passing a security check. Researchers call the trick ClickFix, or a fake CAPTCHA; the FTC has warned about it too.

The one rule that spots every version

A real “prove you’re human” check asks you to do one of three things: tick a box, click a few pictures, or nothing at all. That is the whole repertoire. It never asks you to press keys, open a program, paste something, or run a command.

So the moment a verification step tells you to type or paste anything — Windows+R, a terminal, PowerShell, “just copy this and press Enter” — you can stop right there. It isn’t verification. It’s an instruction to attack your own machine, dressed up as a formality.

Why it fools careful people

It borrows trust you’ve already given: the Cloudflare turnstile, the Google logo, the tick-box you clear without a thought every day. It turns up on ordinary sites, including real ones that have been hacked to serve it. And it frames the dangerous move — running a command — as the boring, expected step. Nothing about it looks like an attack, which is exactly why it works. The newer versions, flagged this September, use the same trick to reach further into home and work networks, so it’s worth knowing cold.

If you see one

Don’t do the steps. Close the tab. If you got as far as pressing Windows+R and a small box opened, close that too — without pasting, without pressing Enter. Nothing has run yet. The whole attack depends on you finishing the keystrokes; right up to that last Enter, you’re fine.

If you already did it

Assume something was installed, and act on that. Disconnect the device from the internet. Run a full scan with security software you trust, or take the machine to someone who can. From a different device, change the passwords that matter — email first, then banking — and switch on two-step verification wherever it’s offered. Then keep half an eye on your accounts for anything you didn’t do. Move promptly and it’s a bad afternoon, not a disaster.

The reassuring part

This attack can’t run itself. It needs your hands on the keyboard — that’s its one weakness, and your one defence. No genuine security check, software fix, or human-verification step will ever ask you to run a command. If something does, you already have your answer: close it, and walk away.

Spotted a mistake? We correct errors within 24 hours and log every one on our corrections page. Tell us: contact@webuser.com.