Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

If a CAPTCHA tells you to press Win + R, open PowerShell or Command Prompt, and paste a command, stop. That is not a normal human check. It is a ClickFix-style malware lure: the page tries to persuade you to run code yourself. Researchers have documented fake verification pages reached through cracked-game downloads, and campaigns that use this approach have targeted browser data and gaming accounts. Simply seeing the page does not mean your PC is infected; running its command is the critical escalation.

What the fake CAPTCHA is really doing

A fake CAPTCHA borrows the look of a familiar verification screen—sometimes with Cloudflare-style branding, a checkbox, or a “verify you are human” message. The trick is not that the CAPTCHA itself exploits your computer. Instead, the page asks you to do something a real CAPTCHA should not require: open a Windows system tool and execute text supplied by the site.

Microsoft describes this social-engineering approach as ClickFix. Attackers use a visual prompt to persuade a person to run a command manually. In some versions, clicking a button puts attacker-controlled text on the clipboard; the page then tells the visitor to press Win + R, paste, and press Enter. The visitor may never see or understand what was copied.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A typical chain looks like this:

  1. You visit a cracked-game page, download mirror, forum, advertisement, or compromised website.
  2. A redirect or page overlay displays a fake verification screen.
  3. The page may manipulate the clipboard or instruct you to copy text.
  4. You are told to open Run, PowerShell, Command Prompt, or another system utility.
  5. You paste and execute the supplied command.
  6. The command retrieves or launches another script or program, which may install a data stealer or other malware.

In one investigated 2026 campaign, LevelBlue described a multistage chain leading to the StealC information stealer. The Swiss National Cyber Security Centre explains that user-initiated execution can make this tactic effective because the activity appears to begin with an action the person deliberately took; that does not mean security software is powerless or that every such command will evade detection.

#1 Best Overall
Sale
Logitech G502 Hero Wired Gaming Mouse - Black
  • HERO Gaming Sensor: Next generation HERO mouse sensor delivers precision tracking up to 25600 DPI with zero smoothing, filtering or acceleration
  • 11 programmable buttons and dual mode hyper-fast scroll wheel: The Logitech wired gaming mouse gives you fully customizable control over your gameplay
  • Adjustable weights: Match your playing style. Arrange up to five 3.6 g weights for a personalized weight and balance configuration
  • LIGHTSYNC technology: Logitech G LIGHTSYNC technology provides fully customizable RGB lighting that can also synchronize with your gaming (requires Logitech Gaming Software)
  • Mechanical Switch Button Tensioning: A metal spring tensioning system and metal pivot hinges are built into left and right computer gaming mouse buttons for a crisp, clean click feel with rapid click feedback

Why cracked-game seekers can be exposed

Researchers have documented cracked-game download URLs among the paths that led visitors to fake CAPTCHA pages. McAfee reported such infection paths. Unofficial download ecosystems also commonly involve redirects, ad networks, file hosts, repacks, patches, and multiple buttons or instructions. That clutter gives criminals opportunities to disguise a malicious prompt as one more routine step.

This is not evidence that every piracy site or game download is part of one campaign. It is a reason to treat unexpected verification prompts and files from unofficial sources as untrusted. Separate from CAPTCHA lures, Malwarebytes has also reported pirated PC-game installers carrying password-stealing malware. The delivery route and campaign differ, but the practical risk is similar: an untrusted download can expose accounts and data.

Rank #2
Sale
Logitech G305 Lightspeed Wireless Gaming Mouse - Black
  • The next-generation optical HERO sensor delivers incredible performance and up to 10x the power efficiency over previous generations, with 400 IPS precision and up to 12,000 DPI sensitivity
  • Ultra-fast LIGHTSPEED wireless technology gives you a lag-free gaming experience, delivering incredible responsiveness and reliability with 1 ms report rate for competition-level performance
  • G305 wireless mouse boasts an incredible 250 hours of continuous gameplay on just 1 AA battery; switch to Endurance mode via Logitech G HUB software and extend battery life up to 9 months
  • Wireless does not have to mean heavy, G305 lightweight mouse provides high maneuverability coming in at only 3.4 oz thanks to efficient lightweight mechanical design and ultra-efficient battery usage
  • The durable, compact design with built-in nano receiver storage makes G305 not just a great portable desktop mouse, but also a great laptop travel companion, use with a gaming laptop and play anywhere

What attackers may be after

Different campaigns use different payloads; there is no single “fake CAPTCHA virus.” Researchers have documented fake-CAPTCHA campaigns associated with Lumma Stealer and Atomic Stealer, while LevelBlue linked a separate campaign to StealC. These examples should not be conflated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An information stealer may look for saved browser passwords, session cookies, autofill data, gaming and email credentials, cryptocurrency-wallet data, VPN or FTP credentials, screenshots, and basic system information. LevelBlue reported that the StealC campaign targeted Steam accounts, Outlook credentials, wallets, browser credentials, system data, and screenshots. CyberProof has likewise described gaming credentials and other sensitive data as targets in a fake-CAPTCHA infostealer chain.

Rank #3
Sale
Razer Basilisk V3 Customizable RGB Wired Ergonomic Gaming Mouse, Black
  • ICONIC ERGONOMIC DESIGN WITH THUMB REST — PC gaming mouse favored by millions worldwide with a form factor that perfectly supports the hand while its buttons are optimally positioned for quick and easy access
  • 11 PROGRAMMABLE BUTTONS — Assign macros and secondary functions across 11 programmable buttons to execute essential actions like push-to-talk, ping, and more
  • HYPERSCROLL TILT WHEEL — Speed through content with a scroll wheel that free-spins until its stopped or switch to tactile mode for more precision and satisfying feedback that’s ideal for cycling through weapons or skills
  • 11 RAZER CHROMA RGB LIGHTING ZONES — Customize each zone from over 16.8 million colors and countless lighting effects, all while it reacts dynamically with over 150 Chroma integrated games
  • OPTICAL MOUSE SWITCHES GEN 2 — With zero unintended misclicks these switches provide crisp, responsive execution at a blistering 0.2ms actuation speed for up to 70 million clicks

Stolen active cookies or authentication tokens can sometimes let an attacker access an account without completing the ordinary password-and-second-factor login flow. That is not inevitable: the impact depends on what was stolen, whether it remains valid, and the service’s protections. It is why changing a password alone may not be enough; revoke active sessions as well.

Other gaming-related ClickFix lures have delivered different payloads. For example, BleepingComputer reported Steam-forum posts directing users to run commands that installed the XMRig cryptocurrency miner. That was a separate forum-based campaign, not the same fake-CAPTCHA StealC operation. A miner can drive unusually high CPU or GPU use, heat, fan noise, and poor performance. Loaders or remote-access malware can have still other effects.

Rank #4
Sale
Redragon M612 Wired RGB Optical Gaming Mouse 8000 DPI Remapping Keys
  • Pentakill, 5 DPI Levels - Geared with 5 redefinable DPI levels (default as: 500/1000/2000/3000/4000), easy to switch between different game needs. Dedicated demand of DPI options between 500-8000 is also available to be processed by software.
  • Any Button is Reassignable - 11 programmable buttons are all editable with customizable tactical keybinds in whatever game or work you are engaging. 1 rapid fire + 2 side macro buttons offer you a better gaming and working experience.
  • Comfort Grip with Details - The skin-friendly frosted coating is the main comfort grip of the mouse surface, which offers you the most enjoyable fingerprint-free tactility. The left side equipped with rubber texture strengthened the friction and made the mouse easier to control.
  • 5 Decent Backlit Modes - Turn the backlit on and make some kills in your gaming battlefield. The hyped dynamic RGB backlit vibe will never let you down when decorating your gaming space, it would be better with other Redragon accessories with lights on.
  • Fatigue Killer with Ergonomic Design - Solid frame with a streamlined and general claw-grip design offers a satisfying and comfortable gaming experience with less fatigue even though after hours of use.

Red flags: stop if you see these

  • The verification says to press Win + R or open PowerShell, Command Prompt, Terminal, or another system utility.
  • The page asks you to paste and run a command, script, or text you did not write.
  • It says to disable Microsoft Defender or another security tool, ignore a warning, or run something as administrator.
  • A supposed human check requires installing an executable or script file, such as an .exe, .msi, .scr, .bat, .cmd, or .ps1.
  • A download button triggers several redirects, a fake browser update, or an unexpected installer.
  • The page uses urgency—such as “verification failed” or “your browser is unsafe”—to push you into acting quickly.

The decisive rule: a webpage should never need you to paste an unknown command into a system tool to prove you are human. A real CAPTCHA asks you to complete an interaction within the page, such as selecting images or checking a box. The Win + R sequence is Windows-specific, but ClickFix-style lures can be adapted to other operating systems with different instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If you only saw the page

If you closed the tab without running a command, opening a downloaded file, or installing anything, that is materially different from executing the lure. Merely viewing a fake CAPTCHA is not proof of infection.

Best Value
Logitech G PRO X2 SUPERSTRIKE Wireless Gaming Mouse - Black/White
  • Designed With Pros, Engineered to Win: Designed alongside the world’s best esports athletes, the Logitech G PRO X2 SUPERSTRIKE wireless gaming mouse delivers the fastest, fully customizable click
  • Dominate with industry-leading speed: 30 ms faster clicks for peak performance in every esports match and deep customization with 10-level actuation points and 5-level rapid trigger reset
  • Haptic Feedback: This breakthrough haptic gaming mouse with Haptic Inductive Trigger System (HITS) gives real-time feedback for an unmatched immersive experience for any game scenario or play style
  • Precision from Within: The HERO 2 sensor in this PC gaming mouse delivers tracking at over 888 IPS, 88 g-force, and up to 44,000 DPI — ensuring the pinpoint accuracy that champions rely on for every play
  • Play Longer : With 60-90 hours battery life and LIGHTSPEED Wireless, this rechargeable gaming mouse(with included USB-A to USB-C cable) delivers lag-free 8 kHz polling for uninterrupted focus
  1. Close the tab and do not paste or execute anything from it.
  2. Check the browser’s download list. Delete unexpected files without opening them.
  3. If you allowed site notifications, remove that permission in your browser’s site settings.
  4. Update Windows and your browser through their normal settings. Run a security scan if a file was downloaded or the browser begins behaving unusually.

If you ran the command or opened the file

Treat an unknown command executed from a webpage as a possible compromise, even if nothing obvious happened. A scan can help, but it cannot undo information already copied off the PC.

  1. Disconnect the affected PC from the internet. Turn off Wi-Fi or unplug Ethernet. Do not use it to sign in to accounts or change passwords.
  2. Use a separate, trusted device to change the passwords for your primary email, Steam or other gaming accounts, Microsoft/Google/Apple accounts, social accounts, and financial services. Prioritize email because it can be used to reset other accounts.
  3. Revoke sessions and tokens. Use each service’s security settings to sign out other devices or revoke active sessions where available. Review recovery email addresses, phone numbers, authenticator methods, and regenerate recovery codes if needed.
  4. Contact your bank or financial provider if payment or banking information may have been exposed. If a crypto wallet may be compromised, use a clean device and seek trusted specialist guidance before moving funds.
  5. Scan the PC. Run Microsoft Defender Offline or a reputable second-opinion scanner. Follow the security product’s instructions and do not assume a detection-free scan proves no data was stolen.
  6. Consider a clean Windows reinstall if an unknown command ran, an infostealer was detected, security tools report persistence or tampering, or you cannot establish what the script did. Back up only essential personal documents, not suspicious programs or scripts. A reinstall is disruptive, but it is a defensible choice when the machine holds work, financial, or other high-value accounts.
  7. Preserve useful details such as the URL, filename, time, and screenshots for a security professional or incident report. Do not revisit the malicious page. Warn contacts if a taken-over account may have sent messages in your name.

Do not change passwords on the potentially infected computer: a stealer could capture the new credentials too. Nor should you assume that removing one detected file makes accounts safe; session revocation and credential recovery are separate tasks.

If you downloaded a game but did not open it

Delete the installer or archive without running it, empty the Recycle Bin, and scan the computer. Review the browser’s download history and check for extensions you did not install. Do not upload a file to an arbitrary online scanner if it could contain personal information or copyrighted material.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you opened or installed the game or its patch from an untrusted source, treat that as a higher-risk event even if there was no fake CAPTCHA. Disconnect the PC, secure accounts from a clean device, and consider a clean reinstall if malware is detected or you cannot determine what ran. A game reinstall alone may not remove a malicious extension or persistence mechanism.

How to reduce the risk

  • Get games from official stores or publisher sites rather than relying on a cracked-game mirror.
  • Keep Windows, your browser, and security protections updated; do not disable protection because a download page tells you to.
  • Use unique passwords and multifactor authentication, and know how to revoke active sessions for important accounts.
  • Treat clipboard text as untrusted. A click that copies a command does not make that command safe.
  • Pause when a verification page asks you to leave the browser for a system tool. Close it rather than trying to “fix” the CAPTCHA.

Microsoft Defender is built into Windows as a baseline protection, and a second-opinion scanner may help investigate a suspicious download. Neither a paid security product nor an antivirus scan makes it safe to run a webpage-supplied command, and neither can reverse credential or cookie theft that already occurred.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.