Security researchers are flagging a nasty malware campaign that turns legitimate websites into bait. A fake CAPTCHA can appear on a real business page, then pressure Windows users into running commands that quietly install malware. The trap looks ordinary at first, which is exactly why it is working.
More than 5,400 compromised sites have reportedly been pulled into the scheme, spread across thousands of organizations and a wide mix of small businesses. Clinics, plumbing companies, online stores and other familiar local names have all shown up in the mix. That means the danger is not limited to sketchy corners of the web, because a trusted site can suddenly become the front door for an attack.
The method is straightforward but slick. A visitor lands on a compromised page, sees what looks like a routine verification challenge, and then gets told to open Windows Run and paste a command. That is the moment the game changes, because the command can pull down malware and launch it on the spot.
What makes the scam especially effective is its use of routine behavior against the user. People are used to CAPTCHAs asking for a checkbox, a picture selection, or a quick proof that they are human. When the prompt feels familiar, the brain tends to relax, and that is when the attacker slips in a dangerous step disguised as part of the process.
Researchers say the campaign has been observed on sites running common platforms, especially WordPress and sometimes PrestaShop. Even more unsettling, investigators still do not know how the attackers initially got inside those sites. The scale suggests this is not a random one-off, but a broad campaign that keeps spreading through ordinary business websites.
The attack also leans on a more unusual trick behind the scenes. Instead of storing all its instructions on a basic web server, the scheme uses the BNB Smart Chain test network and smart contracts to feed compromised sites their next move. That gives the criminals a flexible system that is cheaper to run and harder to knock offline with standard takedown methods.
There is another layer of trouble, too. Some versions of the attack are now skipping the fake CAPTCHA entirely and using WebRTC, a browser technology usually tied to video calls and live communication. In that setup, the browser can receive malicious code through an encrypted connection, which makes the payload easier to hide and harder to spot.
That kind of shift is a reminder that the tactics keep changing even when the goal stays the same. The criminals want the victim to trust the page long enough to take one unsafe step, and then the damage starts fast. The technical details matter to researchers, but the warning for everyday users is simpler than that.
The biggest red flag is also the easiest to remember: a real website should never tell someone to open Windows Run, PowerShell, or Command Prompt just to prove they are human. A CAPTCHA may be annoying, but it should stay inside the browser and never ask for system commands. The second a page pushes instructions outside the browser, it should be treated like a threat.
That advice matters even more for small businesses running their own websites. Security teams are urging site owners to check content management files, look for suspicious JavaScript changes, and remove plugins that are no longer needed. Keeping WordPress, PrestaShop and related tools updated is basic hygiene, but it can make a real difference when attackers are hunting for weak spots.
If a suspicious CAPTCHA appears, the safest move is to close the page and move on. If a command was already pasted, disconnect the device from the internet, scan it with reputable antivirus software, and change important passwords from a different trusted device. A familiar business site can feel harmless in the moment, but this scam is built to turn that comfort into a mistake.
