Israeli Cyber Authority Warns of New Social Engineering Tactic Using Fake CAPTCHA
Hackers trick users into running malicious code disguised as CAPTCHA errors, bypassing browser security and infecting devices with malware
A new cyber threat is exploiting users’ trust in familiar web features by leveraging fake CAPTCHA challenges to install malware. According to the Israel National Cyber Directorate (INCD), attackers are using social engineering tactics to deceive users into compromising their own systems—without traditional hacking methods.
Social engineering refers to a manipulation technique in which hackers trick individuals into performing harmful actions themselves. In this latest campaign, hackers gain access to legitimate websites using stolen credentials. Once inside, they install malicious plugins that simulate CAPTCHA checks—the tests websites use to verify that a user is human.
But instead of validating users, these fake CAPTCHAs appear broken or unresponsive. The user is then prompted to manually intervene, such as by opening the Windows "Run" dialog box, pasting in a code (which is actually malware), and pressing Enter. Once executed, this command can install a wide range of malicious software—from spyware and information stealers to ransomware that locks the entire system.
The attack's effectiveness depends heavily on the credibility and popularity of the compromised site, making it more likely that users will follow the instructions without suspicion. These attacks can even bypass built-in browser protections, such as Google Safe Browsing, allowing them to appear more legitimate.
To protect against these threats, the National Cyber Directorate advises users to examine website addresses carefully, ensuring they are legitimate, free of typos, and secured by HTTPS. They warn against interacting with CAPTCHA prompts on unfamiliar or suspicious websites and emphasize that legitimate CAPTCHA systems will never ask users to download files, install extensions, or run commands on their own device.
Users are urged not to follow instructions that include opening the "Run" dialog, pasting code, or executing unknown commands. If a CAPTCHA asks for any unusual action beyond basic verification, it is best to stop immediately. Keeping systems and software updated is critical to patch known vulnerabilities, and using a firewall can help block attempts to download or run malicious code. Additionally, users should treat emails or messages containing CAPTCHA-related links or requests for account verification with caution, as they may be phishing attempts.
This emerging threat highlights the increasing sophistication of cyber attacks and the need for users to remain vigilant—even when interacting with security tools that typically signal trust. The National Cyber Directorate continues to monitor these developments and encourages the public to stay informed and practice safe online habits.