Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
A CAPTCHA that tells you to press Windows + R, paste a command, run PowerShell, or download a DLL is not verifying that you are human—it is trying to make you launch malware. Google Threat Intelligence Group (GTIG) says the Russian state-sponsored threat group COLDRIVER used fake CAPTCHA pages and the ClickFix social-engineering technique to deploy espionage tools against selected high-value targets in 2025.
What Google found
In a report dated October 20, 2025, Google Threat Intelligence Group attributed the campaign to COLDRIVER, also tracked in this reporting context as Star Blizzard, UNC4057, and Callisto. The activity targeted people and organizations in NGOs, policy circles, dissident communities, government and diplomatic circles, and related high-value groups.
This was not a compromise of genuine Google reCAPTCHA technology. Attackers created or controlled deceptive pages that imitated familiar CAPTCHA interfaces, then used that trust to persuade victims to perform an action on their own Windows computers.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
GTIG observed the operation evolving from May through September 2025. After the group’s earlier LOSTKEYS malware was disclosed on May 7, 2025, GTIG saw no further LOSTKEYS instances and observed new tools approximately five days later.
How the fake CAPTCHA attack works
The campaign used an updated COLDCOPY ClickFix lure. The defensive version of the attack chain looks like this:
#1 Best Overall
- Reliable Plug and Play: The USB receiver provides a reliable wireless connection up to 33 ft (1), so you can forget about drop-outs and delays and you can take it wherever you use your computer
- Type in Comfort: The design of this keyboard creates a comfortable typing experience thanks to the low-profile, quiet keys and standard layout with full-size F-keys, number pad, and arrow keys
- Durable and Resilient: This full-size wireless keyboard features a spill-resistant design (2), durable keys and sturdy tilt legs with adjustable height
- Long Battery Life: MK270 combo features a 36-month keyboard and 12-month mouse battery life (3), along with on/off switches allowing you to go months without the hassle of changing batteries
- Easy to Use: This wireless keyboard and mouse combo features 8 multimedia hotkeys for instant access to the Internet, email, play/pause, and volume so you can easily check out your favorite sites
Targeted lure → counterfeit CAPTCHA → clipboard or download action → victim execution → NOROBOT loader → YESROBOT or MAYBEROBOT backdoor → command-and-control
- A selected target visits a lure page, often after receiving a tailored link or message.
- The page presents a familiar “I’m not a robot” prompt or CAPTCHA-style verification panel.
- After the initial interaction, the page instructs the visitor to use a keyboard shortcut such as Windows + R, paste text, or run a downloaded file.
- The victim-assisted action launches a malicious DLL, in the later chain through Windows’ legitimate
rundll32utility. - A first-stage component contacts attacker infrastructure and retrieves or decrypts additional material.
- A backdoor provides command execution, file access, or further intelligence-collection capability.
Some versions automatically placed text in the clipboard. That removes the need for the victim to type the command and makes it easier to overlook what is being executed. This is the central ClickFix trick: the page falsely claims that a technical action is necessary, while the user unknowingly performs the malware launch.
Free tools Windows power users keep installed
One-click scans. No signup required.
What ClickFix means
Ordinary CAPTCHAs may ask you to click a checkbox, select images, or enter displayed characters. ClickFix pages instead claim that you must leave the normal browser workflow and use an operating-system tool such as the Windows Run dialog, PowerShell, Command Prompt, or Terminal.
That distinction matters more than the appearance of the CAPTCHA. A malicious page can look nearly identical to a legitimate verification widget. The decisive warning signs are the requested action and the context:
- Pressing Windows + R as part of verification.
- Pasting unknown text into a system dialog or terminal.
- Running PowerShell, Command Prompt, or a script.
- Downloading or opening a DLL, executable, archive, or script.
- Disabling security controls or changing unrelated browser settings.
- Allowing notifications or permissions that have nothing to do with proving you are human.
- Completing verification on a domain unrelated to the service you intended to use.
A genuine CAPTCHA should never require you to run an operating-system command. Clicking a checkbox alone is not equivalent to executing malware, and merely seeing a fake CAPTCHA does not prove that a device is infected. The serious risk begins when the victim follows the page’s instructions.
Rank #2
- KEYBOARD: The keyboard works for Windows with hot keys that enable easy access to Media, My Computer, Mute, Volume up/down, and Calculator
- EASY SETUP: Experience simple installation with the USB wired connection
- VERSATILE COMPATIBILITY: This keyboard is designed to work with multiple Windows versions, including Vista, 7, 8, 10 offering broad compatibility across devices.
- SLEEK DESIGN: The elegant black color of the wired keyboard complements your tech and decor, adding a stylish and cohesive look to any setup without sacrificing function.
- FULL-SIZED CONVENIENCE: The standard QWERTY layout of this keyboard set offers a familiar typing experience, ideal for both professional tasks and personal use.
The malware evolved quickly
LOSTKEYS: the predecessor
GTIG disclosed LOSTKEYS in May 2025. The malware could steal files matching selected extensions and directories, collect system information, and inspect running processes. Its infection chain also began with a fake CAPTCHA and ended with the victim being persuaded to execute PowerShell.
LOSTKEYS is best understood as the predecessor, not as another name for the later tools.
NOROBOT: the new DLL loader
NOROBOT was a malicious DLL delivered through the fake CAPTCHA ClickFix lure. The first observed DLL was named iamnotarobot.dll and included an export named humanCheck, matching the lure’s theme.
It retrieved a subsequent stage from a hardcoded command-and-control address. Some versions split cryptographic keys across multiple components, complicating analysis and detection. The victim’s execution of the DLL through rundll32 was a key part of the later delivery chain.
YESROBOT: a short-lived Python backdoor
YESROBOT was a minimal Python-based backdoor that communicated with a hardcoded command-and-control server over HTTPS and used encrypted commands. GTIG observed only two deployments over roughly two weeks in late May 2025.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #3
- 【Ergonomic Design, Enhanced Typing Experience】Improve your typing experience with our computer keyboard featuring an ergonomic 7-degree input angle and a scientifically designed stepped key layout. The integrated wrist rests maintain a natural hand position, reducing hand fatigue. Constructed with durable ABS plastic keycaps and a robust metal base, this keyboard offers superior tactile feedback and long-lasting durability.
- 【15-Zone Rainbow Backlit Keyboard】Customize your PC gaming keyboard with 7 illumination modes and 4 brightness levels. Even in low light, easily identify keys for enhanced typing accuracy and efficiency. Choose from 15 RGB color modes to set the perfect ambiance for your typing adventure. After 30 minutes of inactivity, the keyboard will turn off the backlight and enter sleep mode. Press any key or "Fn+PgDn" to wake up the buttons and backlight.
- 【Whisper Quiet Design】Experience near-silent operation with our whisper-quiet gaming switch, ideal for office environments and gaming setups. The classic volcano switch structure ensures durability and an impressive lifespan of 50 million keystrokes.
- 【IP32 Spill Resistance】Our quiet gaming keyboard is IP32 spill-resistant, featuring 4 drainage holes in the wrist rest to prevent accidents and keep your game uninterrupted. Cleaning is made easy with the removable key cover.
- 【25 Anti-Ghost Keys & 12 Multimedia Keys】Enjoy swift and precise responses during games with the RGB gaming keyboard's anti-ghost keys, allowing 25 keys to function simultaneously. Control play, pause, and skip functions directly with the 12 multimedia keys for a seamless gaming experience. (Please note: Multimedia keys are not compatible with Mac)
Its commands had to be valid Python code, which made routine operator tasks cumbersome. GTIG’s observations suggest that YESROBOT was quickly abandoned as a temporary replacement for LOSTKEYS.
MAYBEROBOT: a more flexible PowerShell backdoor
MAYBEROBOT replaced YESROBOT. It was PowerShell-based and could download and execute files, run commands through cmd.exe, and execute PowerShell blocks. It used a custom command-and-control protocol and did not require a complete Python installation, reducing operational noise.
The backdoor itself remained relatively minimal and relied on operator-supplied commands. Across the campaign, GTIG saw changes to filenames, export names, infrastructure, retrieval paths, cryptographic handling, and the number of intermediate components.
Why use a CAPTCHA?
CAPTCHAs are familiar, repetitive, and often treated as a routine obstacle. That creates what security researchers sometimes call click fatigue: users follow the instructions without closely examining whether the requested action makes sense.
The technique also gives attackers operational advantages:
Rank #4
- Take your gaming skills to the next level: The Logitech G413 SE is a full-size keyboard with gaming-first features and the durability and performance necessary to compete
- PBT keycaps: Heat- and wear-resistant, this computer gaming keyboard features the most durable material used in keycap design
- Tactile mechanical switches: Uncompromising performance is always within reach with this wired gaming keyboard
- Premium color, material and finish: Elevate your gaming setup with this backlit keyboard featuring a sleek, black-brushed aluminum top case and white LED lighting
- 6-Key rollover anti-ghosting performance: Experience reliable key input with this anti-ghosting keyboard versus non-gaming mechanical keyboards
- Victim-assisted execution: a user launches the command instead of an exploit needing to run silently.
- Trust and familiarity: a verification panel looks like normal website behavior.
- Possible defense bypass: manually executed commands may not resemble a conventional malicious download at the initial web-request stage.
- Target filtering: attackers can show the lure only to selected visitors.
- Flexible infrastructure: domains, filenames, stages, and payloads can change without abandoning the basic social-engineering method.
GTIG has not established a definitive public reason for COLDRIVER’s move from its traditional credential-phishing activity toward malware deployment. One GTIG hypothesis is that the group may already have had access to email accounts and contacts and wanted intelligence directly from target devices. That remains an analyst hypothesis, not a confirmed motive.
Who is at risk?
The reported COLDRIVER campaign was targeted, not a claim that every internet user was equally likely to encounter the same espionage infrastructure. High-value targets included NGOs, dissidents, policy advisers, government and diplomatic personnel, former intelligence or military officials, and think tanks.
However, the technique itself is broader than COLDRIVER. Other criminal groups have used fake CAPTCHA ClickFix pages to distribute infostealers, remote-access tools, and other malware. Mandiant has tracked financially motivated fake-CAPTCHA activity since June 2024, and its reporting should not automatically be conflated with the COLDRIVER operation.
Recommended Free Tools
In other words, a fake CAPTCHA may represent a Russian espionage lure, a financially motivated criminal campaign, or another threat entirely. The visual design alone cannot establish attribution.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What users should do
Follow one simple rule: never paste a command because a webpage told you to.
Best Value
- 【65% Compact Design】GEODMAER Wired gaming keyboard compact mini design, save space on the desktop, novel black & silver gray keycap color matching, separate arrow keys, No numpad, both gaming and office, easy to carry size can be easily put into the backpack
- 【Wired Connection】Gaming Keybaord connects via a detachable Type-C cable to provide a stable, constant connection and ultra-low input latency, and the keyboard's 26 keys no-conflict, with FN+Win lockable win keys to prevent accidental touches
- 【Strong Working Life】Wired gaming keyboard has more than 10,000,000+ keystrokes lifespan, each key over UV to prevent fading, has 11 media buttons, 65% small size but fully functional, free up desktop space and increase efficiency
- 【LED Backlit Keyboard】GEODMAER Wired Gaming Keyboard using the new two-color injection molding key caps, characters transparent luminous, in the dark can also clearly see each key, through the light key can be OF/OFF Backlit, FN + light key can switch backlit mode, always bright / breathing mode, FN + ↑ / ↓ adjust the brightness increase / decrease, FN + ← / → adjust the breathing frequency slow / fast
- 【Ergonomics & Mechanical Feel Keyboard】The ergonomically designed keycap height maintains the comfort for long time use, protects the wrist, and the mechanical feeling brought by the imitation mechanical technology when using it, an excellent mechanical feeling that can be enjoyed without the high price, and also a quiet membrane gaming keyboard
- Do not paste unknown text into Run, PowerShell, Command Prompt, Terminal, or a browser developer console.
- Do not run a DLL, script, executable, or archive as part of CAPTCHA verification.
- Do not disable security software to complete a verification step.
- Close the tab and reach the intended service by typing its known address or using a trusted bookmark.
- If text was copied but not executed, clear the clipboard, close the page, and report the URL.
If a command was executed, do not assume that the absence of a pop-up or antivirus alert means the computer is clean. Disconnect the device from the network when appropriate, contact organizational IT or security staff, and avoid using the device for sensitive work until it has been assessed.
What to do after execution
- Only saw the fake CAPTCHA: close the page and report it if possible. Seeing it alone does not establish infection.
- Copied text but did not run it: clear the clipboard, close the page, and report the URL.
- Ran a command but saw no obvious result: treat the endpoint as potentially compromised and escalate it.
- Downloaded or executed a DLL or script: isolate the endpoint, preserve evidence, and involve security personnel or an incident-response provider.
- Used passwords or accessed sensitive accounts afterward: change credentials from a known-clean device and revoke active sessions where possible.
Organizations should preserve the original URL, downloaded files, timestamps, browser history, command-line records, parent-child process relationships, and network connections. Amateur cleanup can destroy evidence or leave an attacker’s access intact.
What security teams should monitor
Static indicators are useful but fragile. Domains rotate, filenames change, and delivery stages are added or removed. Behavioral telemetry provides a more durable detection opportunity.
- A browser spawning PowerShell, Command Prompt, or another shell.
rundll32loading a recently downloaded or user-writable DLL.- Unexpected script execution immediately after a browser interaction.
- New logon scripts or other persistence mechanisms appearing after a suspected lure visit.
- Unusual outbound connections from browsers, PowerShell, Office applications, or DLL loaders.
- Suspicious clipboard activity followed by command-line execution.
- Encrypted traffic to newly registered or otherwise suspicious domains.
- Files and cryptographic components that appear unrelated individually but form a chain when collected together.
Recommended controls include endpoint detection and response, application allowlisting for DLL execution, least-privilege accounts, restrictions on unnecessary scripting, browser and DNS filtering, command-line and clipboard telemetry where appropriate, and security-awareness training built around realistic ClickFix examples.
GTIG lists hashes, domains, and other indicators in its report and associated threat-intelligence collection for registered users. Historical examples include viewerdoconline[.]com, documentsec[.]com, inspectguarantee[.]org, captchanom[.]top, system-healthadv[.]com, and southprovesolutions[.]com. These are indicators associated with the October 2025 reporting period—not proof that every current visit to those domains is malicious or that the infrastructure remains active.
What the attribution does—and does not—mean
GTIG attributes the activity to COLDRIVER and describes the group as Russian state-sponsored. That is a threat-intelligence assessment, not a judicial finding that identifies a specific Russian agency as having ordered every operation.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Nor does the attribution mean that every fake CAPTCHA campaign is Russian or connected to COLDRIVER. The reliable conclusion is narrower: a documented COLDRIVER campaign used fake CAPTCHA pages as ClickFix lures to persuade selected targets to execute espionage tools, while other criminal groups have adopted similar tactics for different purposes.
The most important defensive lesson is independent of attribution. A CAPTCHA asks you to interact with a webpage. It should not ask you to operate the command line, launch a DLL, or weaken your computer’s security.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

