READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Fake CAPTCHA Prompts Have Compromised Over 5,400 Small Business Websites, Netskope Finds

Fake CAPTCHA Prompts Have Compromised Over 5,400 Small Business Websites, Netskope Finds
Netskope Threat Labs says attackers have hijacked more than 5,400 legitimate small-business websites to trick visitors into pasting malware commands into Windows Run, disguised as a routine CAPTCHA check. Separately, Palo Alto Networks' Unit 42 uncovered a two-year-old pay-per-install operation using YouTube gaming channels to spread different malware to hundreds of thousands of viewers. Neither firm knows exactly how the sites were first breached, and no one has been charged.

A visit to an ordinary small business website—a plumber, a clinic, an online store—carries a hidden risk, according to Netskope Threat Labs. The security firm says it has identified more than 5,400 compromised websites tied to over 2,200 organizations worldwide, all rigged to trick visitors into infecting their own machines.

The trap works through a fake CAPTCHA. Instead of the usual "click to prove you're human" box, the compromised page instructs visitors to open the Windows Run dialog and paste in a command. That command, once executed, downloads and launches malware directly, according to Netskope.

Security researchers call this technique ClickFix. It doesn't rely on a software exploit. It relies on habit. People are conditioned to click through CAPTCHAs without much thought, and a convincing fake verification screen on a site they already trust lowers their guard further.

Netskope says the affected sites mostly run WordPress, with some PrestaShop installations as well. The firm has not determined how attackers gained initial access to these sites in the first place, an open question that means the same trick could keep spreading to new victims even after individual sites are cleaned up.

The scale is not static. Netskope says several hundred compromised sites can be live on any given day, and it has recently tracked more than 300 sites contacting the attackers' infrastructure on a typical weekday. That points to an active, ongoing campaign rather than a one-time incident.

The warning sign is straightforward: a legitimate CAPTCHA never asks a user to open Windows Run or paste a command into their computer. If a verification screen does that, it is not verifying anything. It is asking the visitor to run the attack themselves.

A Separate, Larger Ecosystem

The CAPTCHA scheme is not the only malware distribution operation researchers have flagged this month. Unit 42, the threat research arm of Palo Alto Networks, published findings on September 9 describing a distinct pay-per-install cybercrime cluster it calls CL-CRI-1171, active for at least two years.

According to Unit 42 researcher Rem Dudas, this group doesn't build its own malware. It sells infection services to other criminals who want their payloads spread widely, using a single custom loader. Unit 42 says it has identified more than 10,000 distinct loader samples tied to the operation.

One delivery channel ran through YouTube. Unit 42 says it found at least eleven YouTube channels, each with hundreds of thousands of followers, posting legitimate-looking gaming content, tips on frame rates, crash fixes, settings tweaks, that also pushed links to malicious downloads. Unit 42 says it reported the channels to YouTube, which terminated them.

A second channel used SEO poisoning to push trojanized software toward a more corporate audience, according to Unit 42, resulting in infections on endpoints inside critical infrastructure and government entities. Between July 2025 and April 2026, Unit 42 says the same loader delivered three distinct payloads: two never previously reported, which researchers named Docro Hijacker and ARKTunnel, plus a new variant of a backdoor they dubbed Insomnia RAT.

These are two separate operations reported by two separate research teams. Nothing in either report ties CL-CRI-1171 to the ClickFix CAPTCHA campaign, and neither Netskope nor Unit 42 has named the individuals or groups behind these operations. No indictment, arrest, or law enforcement action has been announced against either.

The Fair Question, and What's Unresolved

A reasonable skeptic might ask whether this is being overstated, since fake CAPTCHA and malicious-download scams have existed for years and get flagged by security vendors regularly as part of their business. That's a fair point: Netskope and Palo Alto Networks both sell threat-detection products, and flagging large campaigns is part of how they market those products.

But the specific numbers here—5,400-plus compromised sites, 2,200-plus organizations, 300-plus daily callbacks, 10,000-plus loader samples—are concrete figures from named research teams, not vague estimates. Nothing in the underlying claim that these techniques exist and are actively deployed requires taking the vendors' word on anything beyond what they measured.

What remains unknown is how the WordPress and PrestaShop sites were first breached, whether it was a shared plugin vulnerability, stolen credentials, or something else. Netskope has not published an answer. Small business owners running WordPress sites have no clear indicator today of whether their own site is compromised without direct scanning, and neither firm has published a public list of affected domains.

For everyday users, the practical takeaway is narrower and more actionable: no legitimate website verification will ever ask you to open the Windows Run dialog and paste a command. If one does, close the tab.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

right
Fox NewsThousands of hacked sites trick you into installing malware
unknown
CyberGuyThousands of hacked sites trick you into installing malware
unknown
Jammin' 99.9 FMThousands of hacked sites trick you into installing malware
unknown
WFMDThousands of hacked sites trick you into installing malware
unknown
Jingle TreeThousands of hacked sites trick you into installing malware
unknown
Unit 42 (Palo Alto Networks)Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
unknown
10bmnews.comThousands of hacked sites trick you into installing malware