Experts warn of the dangers of the “I am not a robot” button on suspicious websites
Think twice before clicking! The "I am not a robot" trap on websites

Think twice before clicking! The "I am not a robot" trap on websites
Share
# Think twice before clicking! The "I am not a robot" trap on websites
03.09.2026 – 09:20Last Update 03.09.2026 – 09:20
Share
## The new method of cyber scammers is to strike through a screen users trust. This trap, which looks like a simple "I am not a robot" verification, can unknowingly lead the user to perform a dangerous operation. Here are the details…
## Follow Our News on Google
Be instantly informed about developments.
Add as a preferred source on Google
## Follow Our News on Google
Be instantly informed about developments.
Advertisement
Advertisement
Advertisement
Advertisement
According to Hürriyet; Scammers are resorting to increasingly different methods every day to deceive internet users. A more familiar screen has now been added to scams that started with fake bank messages, followed by cargo notifications, prize and campaign announcements, or fake customer service: the 'I am not a robot' CAPTCHA verification!
Almost everyone has repeatedly checked the box that appears when entering a website on the internet, which usually says 'I am not a robot'. However, cybersecurity experts warn that scammers are using this habit for a new attack method. Moreover, the goal in this method is not just to redirect the user to a fake website.
HOW DOES THE SCAM PROGRESS STEP BY STEP?
Advertisement
Advertisement
Advertisement
Advertisement
The US Federal Trade Commission (FTC) drew attention to this new scam method with a warning issued last month. The agency warned against phishing attacks carried out through fake screens that imitate the CAPTCHA verifications users frequently encounter on the internet.
In real CAPTCHAs, the user is usually asked to complete simple tasks such as typing the letters and numbers on the screen or selecting specific images. However, the situation is completely different in fake CAPTCHAs. The user is asked to run certain commands on their computer under the impression that a security verification is being performed. This is exactly where the real danger begins!
THE DANGER IS GROWING! FAKE CAPTCHA ATTACKS ARE SPREADING
Stating that there have been very serious examples of this recently, IT Expert Osman Demircan said, “The most recent example was the case of placing a fake Cloudflare CAPTCHA screen on compromised websites in the TerminalFix campaign announced by Microsoft on August 28. This time, users were made to open Windows Terminal or PowerShell and run malicious commands. The attack was not limited to information theft either. Multi-stage structures were used that could allow attackers to establish more persistent access on the corporate network. The structures used significantly reduced the probability of detection, providing both persistence and access to more computers and phones.”
Advertisement
Advertisement
Advertisement
Advertisement
Expressing that another example was recently experienced in the tourism sector, Demircan said, “Proofpoint detected that in campaigns using Booking-like reservation themes, victims were persuaded to run PowerShell via a fake CAPTCHA, and this led to the installation of various malware, especially DanaBot. In some campaigns, thousands of phishing messages were used to lure users into the trap.”
HOW TO TELL IF THE CAPTCHA IS REAL OR A FAKE SCREEN PREPARED BY SCAMMERS?
“A real CAPTCHA will absolutely never ask the user to open Windows or the computer's system tools,” said Osman Demircan, adding, “So if you see an instruction like ‘Press Windows + R, press Ctrl + V, press Enter, open PowerShell, run Terminal’, you should understand that you are now facing a scam trap rather than a CAPTCHA verification. Because this is a very strong indicator of a scam,” and continued:
Advertisement
Advertisement
Advertisement
Advertisement
— A normal CAPTCHA may ask you to select traffic lights, bicycles, vehicles, or houses with roofs, type some characters, or click a box. But it will absolutely never direct you to type commands into the operating system. Similarly, a message popping up saying something has been copied to your clipboard the moment you click the CAPTCHA, a file downloading, or being told to ‘run the command to complete verification’ could mean you are completing the final stage required for your computer to be compromised.
— Another important point is the appearance of the site. A fake CAPTCHA may sometimes appear not on a completely fake site, but on a compromised real website. Therefore, one should not simply think, ‘The address looks correct, so I am on a safe site.’ Microsoft and Proofpoint have officially documented through the work of their security researchers that malicious JavaScript is embedded into real sites, redirecting users to fake CAPTCHA screens.
Advertisement
Advertisement
Advertisement
Advertisement
Let's say we fell into this trap without realizing it and pressed the instructed keys. How will we know if our computer or phone has actually been infected with something?
Emphasizing that not every malware shows symptoms, Osman Demircan said, “In fact, the main purpose of malware designed to steal information is to operate as silently as possible. Therefore, the fact that your computer or phone is working normally absolutely does not mean you are safe.”
Stating that some symptoms can still be observed, Demircan said, “Security software (firewall/antivirus) warning about PowerShell, CMD, mshta, or an unknown application, a black command window opening and closing briefly, new programs or browser extensions appearing even though the user did not install them, browser sessions closing unexpectedly, warnings about new device logins to accounts, unknown sessions appearing in email or social media accounts, or unexpected verification messages regarding bank or credit cards can be serious clues that our computer has been infected with malware.”
‘IN NEW ATTACKS, MALWARE DOES NOT JUST DOWNLOAD AND RUN FILES’
“However, especially in new attacks, malware does not just download and run files,” warned Osman Demircan, adding, “In some stages of the ACR Stealer attacks examined by Microsoft's security researchers in 2026, it was observed that the malware was executed in memory and tried to evade classic file-based security controls. The malware could be targeting browser passwords, session tokens, and sensitive documents. And it could be doing this silently in the background,” and added:
“Therefore, if the commands in question were actually executed by the malware, instead of waiting to see ‘Are there any symptoms?’, the device should be considered compromised. Disconnecting from the internet, running a security scan, and changing passwords from another, clean device if possible are among the serious precautions that must be taken. Two-factor authentication must also definitely be enabled.”
IF YOU HAVE FALLEN INTO THE CAPTCHA TRAP, YOUR BANK ACCOUNTS ARE IN DANGER
Stating that malware called infostealers can target usernames and passwords saved in the browser, cookies, session information, email accounts, social media accounts, and cryptocurrency wallets, Osman Demircan underlined that there is also a risk to internet banking:
— It is a very realistic scenario where mobile banking credentials can be stolen directly. In addition, card information saved in the browser, emails from the bank, or password resets performed via a compromised email account can also strengthen the attacker's hand and allow them to take over the account very quickly.
— The probability of session cookies and tokens being stolen is quite high here. The user might think, ‘My password is very strong, so I am safe.’ But some malware can be designed to steal current session information. In such a scenario, the attacker does not always need to crack your password from scratch; they can gain access to your account by stealing current session information. Therefore, this should not be thought of merely at the level of ‘My Facebook/Instagram/TikTok account could be stolen.’ When an email account is compromised, the password reset center for other accounts may also have fallen into the attacker's hands. Using the compromised email account, the attacker can quickly take over other accounts linked to this email address as well.
TAGS:
Next
News
Source: cnnturk.com





