# Fake CAPTCHA scam: do not paste commands to prove you are human

> Microsoft has spotted ClickFix attacks hiding a script in browser cache. The key warning sign is a verification page asking you to run a command.

- Canonical URL: https://techxtelco.com/news/clickfix-fake-captcha-browser-cache/
- Published: 2026-10-06
- Updated: 2026-10-06
- Topics: Security, Technology, News
- Author: Michel Elijah
- Image: https://anrkjmgqmwfosbvyzrzc.supabase.co/storage/v1/object/public/article-images/clickfix-fake-captcha-browser-cache/hero-v1.webp
- Publisher: Tech X Telco (https://techxtelco.com)

A website asking you to paste a command into Windows Run to prove you are human is a warning to stop. Microsoft Threat Intelligence has documented a ClickFix campaign that hides a malicious script in browser cache before persuading the visitor to execute it.

### What you need to know

Do not copy, paste or run commands from a verification page in Run, Terminal or PowerShell. In the campaign Microsoft described, the attacker stages content that looks like a PNG, then relies on the user running a command. Closing the page is preferable to completing those instructions.

Source: [Microsoft Threat Intelligence: ClickFix cache campaign](https://bsky.app/profile/threatintel.microsoft.com/post/3mwwqym7gw72h)

## What changed in this attack?

Microsoft’s 3 October thread describes compromised websites fetching a script disguised as an image into the browser’s cached content. A later command locates the staged material and executes it. The deception separates the visible instruction from the larger payload.

This is not a claim that simply viewing an ordinary PNG executes malware. The important step in the reported chain is the visitor being tricked into running attacker-supplied instructions. Microsoft says later stages target browser and device credentials.

Source: [Microsoft Threat Intelligence: ClickFix cache campaign](https://bsky.app/profile/threatintel.microsoft.com/post/3mwwqym7gw72h)

## The Australian connection is broader than this campaign

ASD’s Australian Cyber Security Centre warned in May about a separate ClickFix campaign involving compromised WordPress sites and Vidar information-stealing malware. It had observed attacks targeting Australian networks and legitimate Australian business websites being used in the attack chain.

That advisory provides local context, rather than proof that the October cache campaign uses Vidar or has a known Australian victim count. A familiar website name also does not guarantee that every prompt currently displayed on it is trustworthy.

Source: [ASD’s ACSC: Australian ClickFix advisory](https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/clickfix-distributing-vidar-stealer-via-wordpress-targeting-australian-infrastructure)

[Callback scams use a similar switch of context, moving a person from an invoice to a phone call controlled by the scammer.](https://techxtelco.com/news/callback-scams-fake-invoice-phone-number/)

## If you saw the prompt

If you have not run the command, leave the page and do not follow its repair or verification instructions. Keep the browser and operating system updated. The ACSC specifically recommends teaching users to avoid executing commands supplied by websites or pop-ups.

Source: [ASD’s ACSC: Australian ClickFix advisory](https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/clickfix-distributing-vidar-stealer-via-wordpress-targeting-australian-infrastructure)

## If you already ran it

Treat the incident as possible malware exposure, even if nothing obvious appeared on screen. For a work computer, tell your IT or security team promptly and follow its incident-response instructions.

1. Record what happened and when, without running the instructions again.

2. Follow the ACSC malware recovery guide: ensure antivirus is enabled and updated, disconnect the affected device from networks and external devices, and run a full scan.

3. Continue through the guide’s recovery steps, including important password changes where appropriate. Seek professional assistance if you are unsure or signs of infection remain.

Source: [ASD’s ACSC: recover from malware](https://www.cyber.gov.au/report-and-recover/recover-from/malware)

[Our passkeys guide can help strengthen account sign-in after recovery; passkeys do not remove malware from a device.](https://techxtelco.com/security/passkeys-setup-and-recovery/)

[If a platform account becomes inaccessible, our Australian complaints guide explains the available support routes.](https://techxtelco.com/security/digital-platform-complaints-australia/)

### Sources and further reading

- [Microsoft Threat Intelligence: ClickFix cache campaign](https://bsky.app/profile/threatintel.microsoft.com/post/3mwwqym7gw72h): Original 13-post thread: staged PNG-disguised script, fake verification, user execution and final warning.

- [ASD’s ACSC: Australian ClickFix advisory](https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/clickfix-distributing-vidar-stealer-via-wordpress-targeting-australian-infrastructure): Separate Australian campaign involving compromised sites and fake CAPTCHAs; prevention guidance.

- [ASD’s ACSC: recover from malware](https://www.cyber.gov.au/report-and-recover/recover-from/malware): Updated antivirus, disconnection, full scan, further recovery and professional assistance.
