Fake CAPTCHA Scam Installs Malware via Keyboard Commands

Fake CAPTCHA Scam Installs Malware via Keyboard Commands

First seen 8 Aug 2026, 17:35 UTC Mb.Ntdwww.theepochtimes.com 93% similarity 67.5

Article Content

Browse articles
ThreatCluster

In June 2026, the FTC issued a consumer alert regarding a fake CAPTCHA scam that tricks users into executing malware on their devices. The scam presents a verification box mimicking legitimate CAPTCHA screens, asking users to perform specific keyboard commands. When users comply, the malware is executed, allowing attackers to harvest sensitive information like passwords and financial credentials. This attack exploits user trust rather than software vulnerabilities, making it particularly insidious. Victims are advised to disconnect from the internet immediately, change their passwords, and run antivirus scans. The scam targets anyone who encounters these fake CAPTCHA prompts, potentially affecting millions of users. Awareness and education on recognizing these scams are crucial for prevention.

Key Points: • The fake CAPTCHA scam tricks users into executing malware via keyboard commands. • Victims risk exposure of sensitive information, including passwords and financial data. • Immediate disconnection from the internet and password changes are critical steps for victims.

ThreatCluster AI How this analysis works

Timeline

2026-06-01
FTC issues consumer alert
The FTC warns the public about a new fake CAPTCHA scam that installs malware through keyboard commands.
Article 1
2026-08-08
Articles published detailing the scam
Both The Epoch Times and NTD report on the fake CAPTCHA scam, providing guidance on how to identify and respond to it.
Article 1
2026-08-08
Public advised on protective measures
The articles emphasize the importance of recognizing the scam and provide steps for victims to secure their accounts.
Article 2

Community

Browse all →