pixelgravitas
Report a Hack

Home/Case Studies/Fake CAPTCHA malware

Case study · Malware removal

A fake Google CAPTCHA locked every visitor out. A manual search missed it.

Short answer: A safety-training provider's WordPress site showed every visitor a full-screen “Google verification” asking for a one-time code. The dashboard looked clean and a manual search of the database and files found nothing. An AI-assisted scan of the site's source found the hidden script, which was removed, and the site now has protection it didn't have on the day it was hacked. The client asked us not to name them.

SymptomFull-screenfake Google check asking visitors for a one-time code
Manual searchMissed itdashboard, database and files looked clean
Found byAI scanan AI-assisted source scan, reviewed by an engineer
NowFirewalledfiltered before traffic reaches the site

At a glance

A lead-generating site
that stopped generating leads.

Safety-training provider (name withheld)Case file
ClientSafety-training provider, name withheld at the client's requestAnonymous
PlatformWordPress with Elementor and a contact formCMS
BeforeNo firewall in front of the siteExposed
ProblemA fake CAPTCHA over every page, asking for a one-time codeHacked
Found byAI-assisted scan of the source, after a manual search failedLocated
NowScript removed; firewall and site protections switched onClean

What visitors saw

A “verification”
that nobody could get past.

Every visitor to the homepage got a full-screen box styled like a Google verification, asking them to enter a one-time code. It couldn't be closed and the page underneath couldn't be used, so enquiries stopped.

A real Google reCAPTCHA never asks for a one-time code and never covers a whole website. The site's genuine reCAPTCHA, on its contact form, sits in the background and doesn't interrupt anyone.

What was happening

Injected code aimed
at the site's visitors.

The site had been compromised and was loading injected JavaScript that drew a fake CAPTCHA over every page. Fake-verification overlays are a well-documented technique that security researchers call “ClickFix”, used in campaigns against WordPress sites such as ShadowCaptcha, reported in August 2025.

The target is the site's visitors, not the owner: the overlay tries to get people to hand over codes or information, or to run something on their own computer.

Why it was hard to find

Clean on the surface.
Not clean underneath.

1

Dashboard: nothing

No strange plugin and no obvious change. Everything in the WordPress admin looked normal.

2

Manual search: nothing

A long search of the database and files by hand came up empty. The code was written to avoid being found by eye or by a simple text search.

3

AI-assisted scan: found

Scanning the site's source with AI assistance identified the file path that loaded the overlay. An engineer checked it and removed it.

What we did

Removed it, then closed
the doors it came through.

1

Found and removed it

After the manual search, an AI-assisted scan of the source located the hidden script, and it was removed.

2

Put a firewall in front

There was no firewall on the day of the hack. Now traffic is filtered before it reaches the site, so known attack patterns and bad bots are stopped at the edge.

3

Switched on site protections

A security layer on the site itself, with its protections enabled, guards the areas this kind of attack goes after.

The lesson

“The scan says clean”
isn't the same as clean.

If the dashboard or a plugin scan says everything is fine but visitors still see something wrong, the site isn't clean yet. Signs to act on straight away:

A popup you didn't addAny “verification”, CAPTCHA or “press these keys” box that covers your pages.
Requests for codesAnything asking visitors for a one-time code, a password or to run a command.
Enquiries stop suddenlyA working contact form that goes quiet overnight is worth checking from a visitor's point of view.Malware removal →

More case studies

See all →

Start here

Seeing something on your site you didn't put there?

Send the URL. We'll check it from a visitor's side and tell you what the cleanup involves, in writing, before any work starts.

  • 1We check the live site the way your visitors see it.
  • 2You get written findings and a fixed quote for the cleanup.
  • 3You decide. Nothing starts until you say yes.

Report a hacked site

Three fields on purpose. We reply within one business day, and we don't add you to a mailing list.

Report a hacked site