Attackers are using fake Cloudflare CAPTCHA pages to trick people into running a command that opens a remote tunnel into their own computers. CSO Online reporter Shweta Sharma covered the scam. The page looks like the familiar verify-you-are-human check you see all over the web. It is not a check. It is a door.
That is the whole game. They are not trying to prove you are human. They are trying to get you to do their work for them.
The trap looks like a page you already trust
Cloudflare is a real company. Millions of sites use its bot check. You have clicked that box so many times you barely read it anymore. Attackers know that. They copy the look of that page and drop it in front of you after a link, a document, or a sketchy site.
A real Cloudflare check stays in the browser. You click a box, or it just lets you through. That is the entire job.
The fake version asks you to leave the browser and run something on your computer. It may tell you to paste a command it already copied to your clipboard, then press Enter. That paste is not a verification code. It is a command that sets up a tunnel from your machine back to the attackers.
What opening a tunnel actually means for you
Think of your PC like a house with locked doors. A tunnel is someone talking you into running a line from your living room out to the road so they can move stuff in and out without knocking.
Once that tunnel is up, the attacker does not need you to click anything else. They can reach into the computer, grab files, steal saved logins, and use the machine as a foothold. For a small business that can mean email, customer lists, and banking sessions. For a household that can mean tax records, photos, and every password the browser remembered.
You will not get a big red warning that says you just got owned. The page may even thank you and send you on your way.
Why this works on regular people
This is a systems problem. The web trained everybody to treat those checks as background noise. You want the article, the login, the tracking page. The CAPTCHA is the speed bump. So when a page says do this extra step to prove you are human, a lot of folks just do it.
It does not take a genius. It takes a good costume and a person in a hurry. I have seen plenty of sharp people fall for stuff like this because they were busy and the page looked official.
A real CAPTCHA will never ask you to do this
- It will never tell you to open the Windows Run box.
- It will never tell you to open PowerShell, Terminal, or Command Prompt.
- It will never ask you to paste a command and press Enter.
- It will never ask you to download a verification program and run it.
If a website is asking you to run something on your computer to prove you are not a robot, you are not verifying anything. You are handing over access. Close the tab. Do not paste. Do not hit Enter to be polite.
If you already did what the page asked
Disconnect that computer from Wi-Fi and Ethernet. Do not keep working on it and hope for the best. Treat it as compromised until someone who knows what they are doing checks it. Change important passwords from a different device you trust, especially email and banking. If this is a work machine, tell whoever handles IT right away. Do not wait until Monday.
This is not the time to be embarrassed. These pages are built to look legitimate. Get the machine cleaned or replaced. Lingering on a box that already opened a tunnel is how a bad afternoon becomes a bad month.
Simple habits that shut this down
- Slow down on any page that says verify, confirm, or prove you are human, then asks for keyboard steps outside the browser.
- Look at the address bar. A random site is not Cloudflare, even if it stole the branding.
- Never paste commands from a website into Run, PowerShell, or a terminal.
- Tell your family and your shop the same rule in one sentence: real checks stay in the browser.
- Keep the browser and the operating system updated. Use a regular account for daily work, not an administrator login.
- If you run a small business, put this in the next staff note. One person in a hurry is all an attacker needs.
The internet is full of locks that only work if you do not hand over the key. This scam is counting on you to be helpful. Do not be helpful to a stranger on the other end of a fake checkbox.
Primary Source: https://www.csoonline.com/article/4216927/fake-cloudflare-captcha-tricks-victims-into-opening-a-tunnel-for-attackers.html
