


Don't turn your CAPTCHA into a GOTCHA that installs malware on your computer
A CAPTCHA is a simple puzzle (such as "select all images with stairs") on a website that verifies whether you are a human and not a robot. This robot check is intended to prevent website abuse. Increasingly, fake CAPTCHAs are appearing, designed to install malware on your device. Criminals use these fake CAPTCHAs to trick you into performing actions that install malicious software. This can lead to data theft and misuse of your IT account.

How do you recognise a fake CAPTCHA?
Criminals create pop-ups that appear to be regular CAPTCHA. However, once you check the box, additional steps follow that have nothing to do with actual verification. An example of a suspicious command is:
Please note: the example assumes Microsoft Windows. This does not mean that macOS is not also vulnerable. Attackers use similar methods to install AppleScript malware on your computer.
Such a screen might look something like this:

These commands execute a command in the background that installs malicious malware. You'll then be hacked immediately.
What are the risks?
This type of malware often remains invisible, but it performs various tasks in the background. It can, among other things:
The impact of a single infected device can be significant. Consider past attacks at other universities.
What can you do?
If you encounter these types of issues, please don't hesitate to contact the security team at CERT-UT. This team is also helpful when in doubt. Together, we keep the university safe.
With thanks to the University Utrecht.