THE MACHINE THRESHOLD
Cybersecurity / EXPLAINER / 2 MIN READ + OPTIONAL DEEP DIVE

A CAPTCHA should not ask you to run a command

Fake verification prompts try to turn a routine web check into code execution on your computer. The requested action is a stronger warning sign than a familiar logo.

AI-assisted synthesis · Published 2026-09-26 · Updated & sources checked 2026-09-26
How we research and correct our work

Judge the requested action before trusting the appearance.

Notice what the page asks you to do

The FTC’s June 2026 alert describes fake human-verification prompts that instruct visitors to paste and run commands on their computers. Its central distinction is simple: a legitimate CAPTCHA does not require device commands. Do not follow that request merely because the page calls it a security check. [1]

A web check should stay a web check
  1. A familiar-looking verification appears
  2. It asks you to run a device command
  3. Stop before pasting or executing
Real CAPTCHAs do not require commands on your computer

A familiar logo can hide a different action

Microsoft’s August 28, 2026 TerminalFix report describes compromised websites showing a counterfeit verification overlay. Interacting with it copied a malicious command to the clipboard; the instructions then directed visitors to paste it into a terminal. The command displayed reassuring status messages while starting the attack. This is Microsoft’s reported campaign, not evidence that every verification prompt is malicious. [2]

If you already followed the instructions

The FTC advises disconnecting from the internet, running a security scan and, from a different device, changing passwords and enabling two-factor authentication when malware may have been installed. Its linked guidance provides the fuller recovery steps. Closing the web page alone should not be treated as proof of recovery. [1]

Go a little deeper

Optional reading · about 1 more minute

The trust decision moved outside the page

Our interpretation: The important boundary is the change from interacting with a website to executing instructions on the computer. Judging only the logo or the reassuring wording misses that change. An instruction can be dangerous even when it is presented as the cure for a problem.

A safe way to explain the trap

Hypothetical example: A page says a video will load after you complete a “verification” in a separate command window. That request is enough reason to stop. You do not need to run the pasted content to find out what it does. This article intentionally provides no attack command.

Original sources

Attributed synthesis, not original reporting. Examples labeled hypothetical or illustrative are explanatory. Reviewing a source does not independently validate its findings.

  1. FTC: how to spot a CAPTCHA scam ↗

    June 2026 consumer alert; attack boundary and recovery advice read September 26. Exact day not established in retrieved body.

  2. Microsoft: TerminalFix campaign analysis ↗

    August 28, 2026 vendor threat report; initial-access section and clipboard behavior read September 26. No prevalence estimate or product-efficacy claim adopted.

Suggest a correction

Know someone who would find this interesting?

Share this story on Facebook ↗ ·

Follow on Facebook ↗ for story highlights and questions to explore next.

Where this question leads next

Follow new explainers and updates →