Industry News

Fake CAPTCHA Scam Uses Blockchain to Deliver Malware

Decrypt · 7 Aug 2026
Key Takeaway Train staff to recognise that legitimate CAPTCHAs never ask you to copy, paste, or run commands on your computer.

Microsoft has uncovered a new attack technique in which hackers compromise legitimate websites and use them to display fake CAPTCHA verification screens. Instead of the usual "prove you're human" test, these fake prompts trick visitors into copying and running malicious commands on their own Windows computers.

What makes this attack notable is how the hackers hide their instructions: they store the malicious code on the BNB blockchain, a public ledger normally used for cryptocurrency transactions. Because blockchain data is decentralised and difficult to take down, this gives attackers a resilient way to serve malware instructions that's harder for defenders to block or remove compared to traditional hosting.

This technique relies on tricking users into manually executing commands, meaning awareness and caution remain a strong line of defence. Businesses should ensure staff know never to copy-paste or run commands from a website prompt, especially ones claiming to be a CAPTCHA or verification step.

Summarised by CISO AI from Decrypt. We link back to every original so you can read it yourself.